AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-19034

HIGH · CVSS 7.2 EPSS 2.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A command injection vulnerability exists in the Shibby Tomato firmware version 1.28.0000, specifically within the new_qoslimit_stop function in the qoslimittc_stop.sh script, allowing remote attackers to execute arbitrary commands by manipulating the wan_iface argument. Organizations still using this outdated firmware should prioritize remediation, as the exploit has been publicly disclosed and could be actively exploited. Users are encouraged to migrate to FreshTomato for improved security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19034
Severity
HIGH
CVSS
7.2
EPSS
2.47%

Original NVD Description

A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.