CVE-2026-10871: OS Command Injection in Shibby Tomato
A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the component Web UI. Such manipulation of the argument ipv6_6rd_borderrelay leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This project is superseded by FreshTomato.
AI Analysis
Technical Summary
This vulnerability in Shibby Tomato 1.28.0000 involves an OS command injection in the start_6rd_tunnel function within the /sbin/rc file of the Web UI component. Specifically, manipulation of the ipv6_6rd_borderrelay argument enables remote attackers to inject and execute arbitrary operating system commands. The vulnerability has a CVSS 4.0 base score of 8.6, indicating high severity with network attack vector, low attack complexity, no privileges required, and no user interaction. The project is no longer maintained and has been superseded by FreshTomato. There is no vendor-provided patch or remediation level indicated in the available data.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary OS commands on affected devices running Shibby Tomato 1.28.0000. This can lead to full system compromise, unauthorized control, and potential disruption of network services. The vulnerability is exploitable remotely without user interaction and requires no privileges, increasing its risk.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the project is superseded by FreshTomato, migrating to FreshTomato or another actively maintained firmware is recommended. Until an official fix is available, restrict remote access to the affected device's Web UI and disable the vulnerable feature if possible.
CVE-2026-10871: OS Command Injection in Shibby Tomato
Description
A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the component Web UI. Such manipulation of the argument ipv6_6rd_borderrelay leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This project is superseded by FreshTomato.
CVSS v4.0
Score 8.6high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Shibby Tomato 1.28.0000 involves an OS command injection in the start_6rd_tunnel function within the /sbin/rc file of the Web UI component. Specifically, manipulation of the ipv6_6rd_borderrelay argument enables remote attackers to inject and execute arbitrary operating system commands. The vulnerability has a CVSS 4.0 base score of 8.6, indicating high severity with network attack vector, low attack complexity, no privileges required, and no user interaction. The project is no longer maintained and has been superseded by FreshTomato. There is no vendor-provided patch or remediation level indicated in the available data.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary OS commands on affected devices running Shibby Tomato 1.28.0000. This can lead to full system compromise, unauthorized control, and potential disruption of network services. The vulnerability is exploitable remotely without user interaction and requires no privileges, increasing its risk.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the project is superseded by FreshTomato, migrating to FreshTomato or another actively maintained firmware is recommended. Until an official fix is available, restrict remote access to the affected device's Web UI and disable the vulnerable feature if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-06-04T15:32:00.393Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a21f664e29bf47b50d67d46
Added to database: 06/04/2026, 22:04:20 UTC
Last enriched: 06/12/2026, 09:49:17 UTC
Last updated: 07/31/2026, 19:22:57 UTC
Views: 93
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.