CVE-2026-19034: Shibby Tomato qoslimittc_stop.sh new_qoslimit_stop os command injection
A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function newqoslimitstop of the file /tmp/qoslimittcstop.sh. Executing a manipulation of the argument waniface can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19034?
CVE-2026-19034 has a severity rating of 7.2, categorized as high.
How do I fix CVE-2026-19034?
To mitigate CVE-2026-19034, upgrade to a patched version of Shibby Tomato that addresses the OS command injection vulnerability.
What type of vulnerability is CVE-2026-19034?
CVE-2026-19034 is classified as an OS command injection vulnerability.
Can CVE-2026-19034 be exploited remotely?
Yes, CVE-2026-19034 can be exploited remotely through manipulation of the wan_iface argument.
What effect does CVE-2026-19034 have on system integrity?
CVE-2026-19034 allows an attacker to execute arbitrary OS commands, potentially compromising system integrity.