PT-2026-46399 · Shibby · Tomato

·

CVE-2026-10873

·

Published

2026-06-04

·

Updated

2026-06-04

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Shibby Tomato version 1.28.0000
Description An OS command injection flaw exists in the Web UI component within the rstats path() function of the /bin/rstats file. This issue allows a remote attacker to execute arbitrary system commands through manipulation.
Recommendations Update Shibby Tomato version 1.28.0000 to FreshTomato, as the original project has been superseded.

Exploit

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10873

Affected Products

Tomato