CVE-2026-10870
Shibby Tomato Web UI rc start_dhcpc os command injection
CVSS Score
7.2
EPSS Score
0.1%
EPSS Percentile
32th
A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the component Web UI. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. This project is superseded by FreshTomato.
| CWE | CWE-78 CWE-77 |
| Vendor | shibby |
| Product | tomato |
| Published | Jun 4, 2026 |
| Last Updated | Jun 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for shibby tomato
Be the first to know when new high vulnerabilities affecting shibby tomato are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Shibby / Tomato
1.28.0000
References
vuldb.com: https://vuldb.com/vuln/368360 vuldb.com: https://vuldb.com/vuln/368360/cti vuldb.com: https://vuldb.com/cve/CVE-2026-10870 vuldb.com: https://vuldb.com/submit/831856 gitee.com: https://gitee.com/WH-YHUST/tomato-rc-nvram-cve/blob/master/gitee-cve-disclosure/advisories/en/01-start_dhcpc.md gitee.com: https://gitee.com/WH-YHUST/tomato-rc-nvram-cve/blob/master/gitee-cve-disclosure/advisories/zh/01-start_dhcpc.md
Credits
๐ WH-YHUST (VulDB User) VulDB CNA Team