Unknown · Shibby Tomato · CVE-2026-19036
**Name of the Vulnerable Software and Affected Versions**
Shibby Tomato version 1.28.0000
**Description**
A remote OS command injection flaw exists in the `sub 40F88C()` function within the `/tmp/ppp/wanoptions` file. This issue occurs when the `ppp custom` argument is manipulated, allowing an attacker to execute arbitrary operating system commands remotely.
**Recommendations**
As a temporary workaround, restrict access to the `ppp custom` argument in the `/tmp/ppp/wanoptions` file to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.