Impact
An OS command injection flaw exists in the new_qoslimit_start function of Shibby Tomato firmware 1.28.0000. Manipulating the new_qoslimit_enable argument allows an attacker to inject arbitrary operating system commands into the router's process. The flaw can be exploited remotely, giving attackers the ability to run commands with the device's operating‑system privileges, potentially compromising confidentiality, integrity, and availability.
Affected Systems
Shibby Tomato routers running firmware version 1.28.0000 are affected. The vulnerability resides in /etc/qoslimit, and no later releases are indicated as safe in the available data.
Risk and Exploitability
The CVSS score of 8.6 denotes high severity. EPSS data is not available, but a publicly available exploit demonstrates that attackers can use this flaw. The vulnerability is not listed in CISA's KEV catalog. Because the flaw permits remote OS command execution, operators who have not applied a patch face a significant risk of total device compromise.
OpenCVE Enrichment