CVE-2026-19036: A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom re
A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This project is superseded by FreshTomato.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-19036
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-19036 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Shibby Tomato
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-19035: A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the funct…nvd · 2026-08-06
- highCVE-2026-19034: A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is t…nvd · 2026-08-06
- highCVE-2026-16097: A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_4…nvd · 2026-07-18
- highCVE-2026-16096: A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the…nvd · 2026-07-18
- highCVE-2026-16095: A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is…nvd · 2026-07-18
- highCVE-2026-15548: A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerabilit…nvd · 2026-07-13
More from NVD Recent CVEs
- highCVE-2026-19190: A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part …2026-08-07
- unknownCVE-2026-49746: Software installed and run as a non-privileged user may conduct improper GPU system calls to c…2026-08-07
- unknownCVE-2026-45204: Software installed and run as a non-privileged user may conduct improper GPU system calls to t…2026-08-07
- unknownCVE-2026-45198: Kernel software from a non-secure operating system on a platform with Trusted Execution Enviro…2026-08-07
- highCVE-2026-19189: A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue …2026-08-07