CyberRota Analysis
AI-GeneratedA command injection vulnerability exists in the new_qoslimit_start function of Shibby Tomato 1.28.0000, allowing remote attackers to execute arbitrary OS commands by manipulating the new_qoslimit_enable argument. Organizations still using this version of Shibby Tomato should prioritize patching or migrating to FreshTomato, as the exploit is publicly available and poses a significant security risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.