What is CVE-2026-19034?
A remote OS command injection vulnerability was identified in Shibby Tomato 1.28.0000, affecting the `new_qoslimit_stop` function in `/tmp/qoslimittc_stop.sh` via the `wan_iface` argument. Attackers can execute arbitrary commands on the system; the device should be immediately isolated from the network and usage halted until an official patch is applied.
Azərbaycanca: Shibby Tomato 1.28.0000 proqramında `/tmp/qoslimittc_stop.sh` faylındakı `new_qoslimit_stop` funksiyasında `wan_iface` arqumenti vasitəsilə uzaqdan OS əmr inyeksiyası (OS command injection) zəifliyi aşkarlanıb. Bu zəiflikdən istifadə edərək təcavüzkar sistemdə ixtiyari əmrlər icra edə bilər; cihaz dərhal şəbəkədən təcrid edilməli və rəsmi yamaq tətbiq olunana qədər istifadə dayandırılmalıdır.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: Shibby
FAQ2
What does this vulnerability in Shibby Tomato 1.28.0000 allow an attacker to do?
It is an OS command injection vulnerability. An attacker can execute arbitrary commands on the system via the `wan_iface` argument in the `new_qoslimit_stop` function.
What should I do if my device is affected by this vulnerability?
The device should be immediately isolated from the network and its usage halted until an official patch is applied.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.