What is CVE-2026-19035?
A remote OS command injection vulnerability was found in Shibby Tomato 1.28.0000, affecting the `new_qoslimit_start` function in `/etc/qoslimit` via the `new_qoslimit_enable` argument. This could allow unauthorized command execution on affected network devices. Users are advised to temporarily disable the rule or await a patch from the vendor.
Azərbaycanca: Shibby Tomato 1.28.0000 versiyasında `/etc/qoslimit` faylındakı `new_qoslimit_start` funksiyasında `new_qoslimit_enable` arqumentinin idarə edilməsi ilə uzaqdan OS command injection zəifliyi aşkarlanıb. Bu, təsirlənən şəbəkə cihazlarında icazəsiz əmrlərin icrasına səbəb ola bilər. İstifadəçilərə müvəqqəti olaraq qaydanı deaktiv etmək və ya istehsalçıdan yeniləmə gözləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which version of Shibby Tomato is affected by CVE-2026-19035?
CVE-2026-19035 affects Shibby Tomato version 1.28.0000.
What is recommended for users to mitigate CVE-2026-19035?
Users are advised to temporarily disable the rule or await a patch from the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.