top of page
perceptive_background_267k.jpg

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation…

Published:

6 August 2026 at 00:00:00

Alert date:

6 August 2026 at 15:00:34

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure

A critical OS command injection vulnerability has been identified in Shibby Tomato version 1.28.0000. The vulnerability exists in the function new_qoslimit_start within the file /etc/qoslimit. An attacker can manipulate the argument new_qoslimit_enable to inject arbitrary OS commands. The attack can be initiated remotely without requiring physical access. A public exploit is already available, increasing the risk of active exploitation. The affected product, Shibby Tomato, is a router firmware project that has since been superseded by FreshTomato. Users are advised to migrate to FreshTomato or apply any available mitigations. The vulnerability has been catalogued in VulDB and the NVD.

Technical details

Mitigation steps:

Affected products:

Shibby Tomato 1.28.0000

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page