CVE-2026-19035: Shibby Tomato qoslimit new_qoslimit_start os command injection
A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function newqoslimitstart of the file /etc/qoslimit. The manipulation of the argument newqoslimitenable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply a compensating control by restricting network access to the affected QoS limit functionality on Shibby Tomato (which includes /etc/qoslimit and new_qoslimit_start) to prevent remote exploitation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19035?
CVE-2026-19035 has a severity rating of high, with a score of 7.2.
What type of vulnerability is CVE-2026-19035?
CVE-2026-19035 is an OS command injection vulnerability.
How do I fix CVE-2026-19035?
To fix CVE-2026-19035, update Shibby Tomato to a patched version that addresses the new_qoslimit_start issue.
Can CVE-2026-19035 be exploited remotely?
Yes, CVE-2026-19035 can be exploited remotely due to its nature of OS command injection.
What function in Shibby Tomato is affected by CVE-2026-19035?
CVE-2026-19035 affects the function new_qoslimit_start located in the file /etc/qoslimit.