FR
live
High CVSS 7.2

CVE-2026-19036

A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato.

What this means

Exposure
Exploitable remotely over the network, with a privileged account and with no action from the victim.
Impact
An attacker can read sensitive data, modify or destroy data and take the service offline.
Weakness
Unfiltered input is concatenated into a command, letting the attacker append their own.
Likelihood
Its EPSS score puts short-term exploitation in a middle band: neither negligible nor imminent.

What to doFold into the next patch cycle.

Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.

Published
6 August 2026
CVSS
7.2 (v3.1) CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
2.04% probability of exploitation within 30 days · above 80% of all CVEs
Weakness
CWE-77CWE-78
Sources
nvd
References

Type at least two characters.

navigate open esc dismiss