Sceawere
Vulnerability Detail
CVE-2026-19034UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Shibby Tomato wan_iface Command Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 2d ago
- Vendor
- —
- Product
- N/A
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-08-06T11:16:29.777Z",
"pubdate": "2026-08-06T11:16:29.777Z",
"executiveSummary": "A critical OS command injection vulnerability has been identified within Shibby Tomato version 1.28.0000. The vulnerability resides in the function new_qoslimit_stop located in the script file /tmp/qoslimittc_stop.sh. Specifically, improper neutralization of user-supplied input passed to the argument wan_iface enables remote threat actors to inject and execute arbitrary operating system commands with the privileges of the underlying web or script execution context.\nThe flaw allows unauthenticated remote attackers to compromise the confidentiality, integrity, and availability of the affected routing hardware. Successful exploitation bypasses standard input validation controls inherent to network management interfaces, posing a severe risk to network infrastructure. Because Shibby Tomato 1.28.0000 has been officially superseded by FreshTomato, no direct vendor patches are anticipated for this legacy branch. Consequently, risk mitigation relies heavily on hardening access controls or upgrading to the supported successor project.",
"technicalDetails": "The vulnerability is an OS command injection flaw stemming from inadequate sanitization and filtering of parameters processed by shell scripts within the firmware. The vulnerable component is the new_qoslimit_stop function situated within the shell script file /tmp/qoslimittc_stop.sh. The specific parameter failing validation is wan_iface.\nDuring execution, the application constructs system commands dynamically by concatenating external input derived from the wan_iface argument directly into shell execution contexts without sufficient escaping or argument separation. This architectural design flaw permits an attacker to inject shell metacharacters—such as semicolons, pipe symbols, or backticks—directly into the input stream, terminating the intended command sequence and appending arbitrary system-level instructions.\nThe attack vector is network-accessible, allowing remote attackers to transmit maliciously crafted HTTP requests or interface parameters that reach the vulnerable endpoint. Exploitation requires no prior authentication or administrative privileges, lowering the barrier to entry for potential adversaries. When the affected function processes the malicious payload within /tmp/qoslimittc_stop.sh, the underlying operating system executes the attacker-supplied commands with the elevated privileges typically associated with root or administrative router operations.\nThe post-exploitation impact includes complete system compromise, arbitrary code execution, manipulation of network traffic routing, extraction of sensitive configuration data, and potential utilization of the compromised device as a pivot point for lateral movement within the local area network. The affected product version is strictly Shibby Tomato 1.28.0000, which is obsolete and superseded by FreshTomato."
}