


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation…
Published:
5 augustus 2026 om 22:00:00
Alert date:
6 augustus 2026 om 13:00:34
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A critical OS command injection vulnerability has been identified in Shibby Tomato version 1.28.0000. The vulnerability exists in the function new_qoslimit_start within the file /etc/qoslimit. An attacker can manipulate the argument new_qoslimit_enable to inject arbitrary OS commands. The attack can be initiated remotely without requiring physical access. A public exploit is already available, increasing the risk of active exploitation. The affected product, Shibby Tomato, is a router firmware project that has since been superseded by FreshTomato. Users are advised to migrate to FreshTomato or apply any available mitigations. The vulnerability has been catalogued in VulDB and the NVD.
Technical details
Mitigation steps:
Affected products:
Shibby Tomato 1.28.0000
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-19035
https://gitee.com/WH-YHUST/tomato-rc-qos-ppp-cve/blob/master/advisories/en/02-new_qoslimit_start.md
https://vuldb.com/cve/CVE-2026-19035
https://vuldb.com/submit/863667
https://vuldb.com/vuln/386454
https://vuldb.com/vuln/386454/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
