Impact
The vulnerability allows an attacker to inject arbitrary operating‑system commands by manipulating the wan_iface parameter in the new_qoslimit_stop function located in /tmp/qoslimittc_stop.sh. The flaw is a classic OS command injection, classified as CWE‑77 and CWE‑78. Successful exploitation would give the attacker full control over the device’s command execution, potentially enabling complete compromise of the embedded system.
Affected Systems
The flaw is present in Shibby Tomato firmware version 1.28.0000. Devices running this build are directly affected. No other versions are listed.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the advisory confirms that the exploit is publicly disclosed and can be launched remotely. Since the flaw can be triggered remotely through the wan_iface argument, an attacker with network access can achieve remote code execution without local privilege escalation.
OpenCVE Enrichment