{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/tomato-1.28.0000/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-19034"},{"cvss":7.2,"id":"CVE-2026-19035"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Tomato (1.28.0000)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Shibby"],"content_html":"\u003cp\u003eShibby Tomato version 1.28.0000 contains a critical vulnerability involving OS command injection within the new_qoslimit_stop function located in the script /tmp/qoslimittc_stop.sh. An attacker can reach this function by providing malicious input to the wan_iface argument. Because this script executes system-level commands, manipulating this input allows for arbitrary command execution on the underlying Linux-based networking device. This vulnerability is of significant concern as the affected software is widely deployed on home and small-office wireless routers. The project has been superseded by FreshTomato, and users are advised to migrate, as no patches are expected for this legacy firmware. Publicly available exploit proof-of-concept code has been disclosed, increasing the likelihood of opportunistic exploitation in the wild.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a target device running the legacy Shibby Tomato firmware version 1.28.0000.\u003c/li\u003e\n\u003cli\u003eThe attacker gains access to the administrative web interface of the router (or interacts with the interface if exposed to the WAN).\u003c/li\u003e\n\u003cli\u003eThe attacker identifies the request handler responsible for triggering QoS settings, specifically targeting the new_qoslimit_stop function.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts an HTTP request containing an injected payload within the 'wan_iface' parameter.\u003c/li\u003e\n\u003cli\u003eThe web server process passes the attacker-supplied input directly to the /tmp/qoslimittc_stop.sh shell script without sufficient sanitization.\u003c/li\u003e\n\u003cli\u003eThe shell script executes the payload with the privileges of the web service account.\u003c/li\u003e\n\u003cli\u003eThe attacker establishes a reverse shell or executes secondary payloads to maintain persistence or exfiltrate configuration data.\u003c/li\u003e\n\u003cli\u003eThe final objective is full compromise of the networking device to facilitate man-in-the-middle attacks or lateral movement within the local network.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker to execute arbitrary OS commands with elevated privileges on the target router. This provides complete control over the device, enabling traffic interception, password extraction, configuration modification, and the use of the router as a pivot point for further attacks on the internal network. Given the ubiquity of these devices, this vulnerability poses a high risk to small-office and residential environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security operations and IT management:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate all devices currently running Shibby Tomato 1.28.0000 to the active FreshTomato distribution or other supported firmware as the project is superseded.\u003c/li\u003e\n\u003cli\u003eDisable remote management access on the router's web interface to mitigate external exploitation risks (CVE-2026-19034).\u003c/li\u003e\n\u003cli\u003eMonitor firewall logs for unexpected outbound traffic from router management interfaces to unknown remote endpoints.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T13:24:10Z","date_published":"2026-08-06T11:23:13Z","id":"https://feed.craftedsignal.io/briefs/2026-08-shibby-tomato-rce/","summary":"Shibby Tomato version 1.28.0000 is vulnerable to remote OS command injection via the wan_iface parameter in the new_qoslimit_stop function, allowing unauthenticated or authenticated administrative attackers to execute arbitrary code.","title":"Remote OS Command Injection in Shibby Tomato","url":"https://feed.craftedsignal.io/briefs/2026-08-shibby-tomato-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Tomato (1.28.0000)","version":"https://jsonfeed.org/version/1.1"}