Shibby Tomato是Shibby个人开发者的一个第三方路由器固件。 Shibby Tomato 1.28.0000版本存在操作系统命令注入漏洞,该漏洞源于Web UI组件中文件/sbin/rc的start_6rd_tunnel函数对参数ipv6_6rd_borderrelay的操作导致os命令注入,可能导致远程攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-10872 | 7.2 HIGH | Shibby Tomato Web UI rc start_vpnserver os command injection |
| CVE-2026-10873 | 7.2 HIGH | Shibby Tomato Web UI rstats rstats_path os command injection |
| CVE-2026-10870 | 7.2 HIGH | Shibby Tomato Web UI rc start_dhcpc os command injection |
No comments yet