Impact
A flaw in the sub_40F88C function of the /tmp/ppp/wanoptions file in Shibby Tomato 1.28.0000 allows an unauthenticated attacker to inject arbitrary operating system commands by manipulating the ppp_custom argument. The vulnerability can be triggered remotely, enabling an attacker to execute commands with the privileges of the ppp daemon, potentially leading to full system compromise. The weakness is reflected in CWE-77 and CWE-78, which indicate unsafe command handling and unsanitized input usage.
Affected Systems
The affected product is Shibby Tomato version 1.28.0000. No other product or version information is disclosed in the advisory.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, and while a public exploitation code is available, the EPSS metric is not provided, meaning no quantified risk probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via network access that can supply the ppp_custom payload.
OpenCVE Enrichment