Description
A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.
Published: 2026-08-06
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw exists in the new_qoslimit_start function of Shibby Tomato firmware 1.28.0000. Manipulating the new_qoslimit_enable argument allows an attacker to inject arbitrary operating system commands into the router's process. The flaw can be exploited remotely, giving attackers the ability to run commands with the device's operating‑system privileges, potentially compromising confidentiality, integrity, and availability.

Affected Systems

Shibby Tomato routers running firmware version 1.28.0000 are affected. The vulnerability resides in /etc/qoslimit, and no later releases are indicated as safe in the available data.

Risk and Exploitability

The CVSS score of 8.6 denotes high severity. EPSS data is not available, but a publicly available exploit demonstrates that attackers can use this flaw. The vulnerability is not listed in CISA's KEV catalog. Because the flaw permits remote OS command execution, operators who have not applied a patch face a significant risk of total device compromise.

Generated by OpenCVE AI on August 6, 2026 at 14:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router firmware to the latest Shibby Tomato release or transition to FreshTomato, which removes the vulnerable code.
  • Restrict access to the new_qoslimit_* endpoints by allowing only authenticated and privileged users, and block the administrative interface from external networks.
  • Monitor the router's logs for attempts to alter qoslimit settings and review them regularly for anomalous activity that could indicate injection attempts.

Generated by OpenCVE AI on August 6, 2026 at 14:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.
Title Shibby Tomato qoslimit new_qoslimit_start os command injection
First Time appeared Shibby
Shibby tomato
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:shibby:tomato:*:*:*:*:*:*:*:*
Vendors & Products Shibby
Shibby tomato
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-06T15:02:49.287Z

Reserved: 2026-08-06T05:47:38.934Z

Link: CVE-2026-19035

cve-icon Vulnrichment

Updated: 2026-08-06T15:02:38.807Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T14:15:13Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')