CyberRota Analysis
AI-GeneratedA command injection vulnerability exists in the Shibby Tomato firmware version 1.28.0000, specifically within the new_qoslimit_stop function in the qoslimittc_stop.sh script, allowing remote attackers to execute arbitrary commands by manipulating the wan_iface argument. Organizations still using this outdated firmware should prioritize remediation, as the exploit has been publicly disclosed and could be actively exploited. Users are encouraged to migrate to FreshTomato for improved security.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.