Sceawere

Vulnerability Detail

CVE-2026-19034UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Shibby Tomato wan_iface Command Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
2d ago
Vendor
Product
N/A
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-06T11:16:29.777Z",
  "pubdate": "2026-08-06T11:16:29.777Z",
  "executiveSummary": "A critical OS command injection vulnerability has been identified within Shibby Tomato version 1.28.0000. The vulnerability resides in the function new_qoslimit_stop located in the script file /tmp/qoslimittc_stop.sh. Specifically, improper neutralization of user-supplied input passed to the argument wan_iface enables remote threat actors to inject and execute arbitrary operating system commands with the privileges of the underlying web or script execution context.\nThe flaw allows unauthenticated remote attackers to compromise the confidentiality, integrity, and availability of the affected routing hardware. Successful exploitation bypasses standard input validation controls inherent to network management interfaces, posing a severe risk to network infrastructure. Because Shibby Tomato 1.28.0000 has been officially superseded by FreshTomato, no direct vendor patches are anticipated for this legacy branch. Consequently, risk mitigation relies heavily on hardening access controls or upgrading to the supported successor project.",
  "technicalDetails": "The vulnerability is an OS command injection flaw stemming from inadequate sanitization and filtering of parameters processed by shell scripts within the firmware. The vulnerable component is the new_qoslimit_stop function situated within the shell script file /tmp/qoslimittc_stop.sh. The specific parameter failing validation is wan_iface.\nDuring execution, the application constructs system commands dynamically by concatenating external input derived from the wan_iface argument directly into shell execution contexts without sufficient escaping or argument separation. This architectural design flaw permits an attacker to inject shell metacharacters—such as semicolons, pipe symbols, or backticks—directly into the input stream, terminating the intended command sequence and appending arbitrary system-level instructions.\nThe attack vector is network-accessible, allowing remote attackers to transmit maliciously crafted HTTP requests or interface parameters that reach the vulnerable endpoint. Exploitation requires no prior authentication or administrative privileges, lowering the barrier to entry for potential adversaries. When the affected function processes the malicious payload within /tmp/qoslimittc_stop.sh, the underlying operating system executes the attacker-supplied commands with the elevated privileges typically associated with root or administrative router operations.\nThe post-exploitation impact includes complete system compromise, arbitrary code execution, manipulation of network traffic routing, extraction of sensitive configuration data, and potential utilization of the compromised device as a pivot point for lateral movement within the local area network. The affected product version is strictly Shibby Tomato 1.28.0000, which is obsolete and superseded by FreshTomato."
}