PT-2026-46383 · Shibby · Tomato

Wh-Yhust

·

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2026-10870

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start dhcpc of the file /sbin/rc of the component Web UI. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This project is superseded by FreshTomato.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-10870

Affected Products

Tomato