PT-2026-46393 · Shibby · Tomato

·

CVE-2026-10871

·

Published

2026-06-04

·

Updated

2026-06-04

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Shibby Tomato version 1.28.0000
Description An OS command injection issue exists in the Web UI component within the /sbin/rc file. The flaw occurs in the start 6rd tunnel() function when the ipv6 6rd borderrelay argument is manipulated, allowing a remote attacker to execute arbitrary system commands.
Recommendations Update Shibby Tomato version 1.28.0000 to FreshTomato. As a temporary mitigation, restrict access to the Web UI component to prevent remote manipulation of the ipv6 6rd borderrelay argument.

Exploit

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10871

Affected Products

Tomato