


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation…
Published:
6 August 2026 at 00:00:00
Alert date:
6 August 2026 at 15:00:34
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A critical OS command injection vulnerability has been identified in Shibby Tomato version 1.28.0000. The vulnerability exists in the function new_qoslimit_start within the file /etc/qoslimit. An attacker can manipulate the argument new_qoslimit_enable to inject arbitrary OS commands. The attack can be initiated remotely without requiring physical access. A public exploit is already available, increasing the risk of active exploitation. The affected product, Shibby Tomato, is a router firmware project that has since been superseded by FreshTomato. Users are advised to migrate to FreshTomato or apply any available mitigations. The vulnerability has been catalogued in VulDB and the NVD.
Technical details
Mitigation steps:
Affected products:
Shibby Tomato 1.28.0000
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-19035
https://gitee.com/WH-YHUST/tomato-rc-qos-ppp-cve/blob/master/advisories/en/02-new_qoslimit_start.md
https://vuldb.com/cve/CVE-2026-19035
https://vuldb.com/submit/863667
https://vuldb.com/vuln/386454
https://vuldb.com/vuln/386454/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
