Description
A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato.
Published: 2026-08-06
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the sub_40F88C function of the /tmp/ppp/wanoptions file in Shibby Tomato 1.28.0000 allows an unauthenticated attacker to inject arbitrary operating system commands by manipulating the ppp_custom argument. The vulnerability can be triggered remotely, enabling an attacker to execute commands with the privileges of the ppp daemon, potentially leading to full system compromise. The weakness is reflected in CWE-77 and CWE-78, which indicate unsafe command handling and unsanitized input usage.

Affected Systems

The affected product is Shibby Tomato version 1.28.0000. No other product or version information is disclosed in the advisory.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, and while a public exploitation code is available, the EPSS metric is not provided, meaning no quantified risk probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via network access that can supply the ppp_custom payload.

Generated by OpenCVE AI on August 6, 2026 at 13:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Shibby Tomato to the latest released version or apply the vendor‑supplied patch for sub_40F88C
  • If an immediate update is unavailable, isolate the affected device from untrusted networks and enforce strict input validation on the ppp_custom field or disable the feature if it is not required
  • Use network segmentation and firewall rules to block suspicious configuration traffic to the device

Generated by OpenCVE AI on August 6, 2026 at 13:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato.
Title Shibby Tomato wanoptions sub_40F88C os command injection
First Time appeared Shibby
Shibby tomato
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:shibby:tomato:*:*:*:*:*:*:*:*
Vendors & Products Shibby
Shibby tomato
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-06T12:00:13.149Z

Reserved: 2026-08-06T05:47:42.809Z

Link: CVE-2026-19036

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T14:15:13Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')