What is CVE-2026-19036?
CVE-2026-19036 is a security flaw in Shibby Tomato 1.28.0000 that allows OS command injection. It affects the `sub_40F88C` function in the `/tmp/ppp/wanoptions` file through manipulation of the `ppp_custom` argument. The vulnerability can be exploited remotely, and a public exploit is available, so immediate patching is recommended.
Azərbaycanca: CVE-2026-19036 Shibby Tomato 1.28.0000 proqram təminatında aşkarlanmış təhlükəsizlik zəifliyidir. `/tmp/ppp/wanoptions` faylındakı `sub_40F88C` funksiyasında `ppp_custom` arqumentinin düzgün işlənməməsi nəticəsində əməliyyat sistemi əmri inyeksiyası (OS command injection) mümkündür. Bu zəiflik uzaqdan istismar edilə bilər və istismar kodu ictimaiyyətə açıqlanıb, istifadəçilərə dərhal proqram təminatını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: Shibby
FAQ2
Which version of Shibby Tomato software is affected by CVE-2026-19036?
This vulnerability affects Shibby Tomato version 1.28.0000.
In which function and file does the exploitation of CVE-2026-19036 occur?
The exploitation occurs in the `sub_40F88C` function within the `/tmp/ppp/wanoptions` file, through the `ppp_custom` argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.