CVE-2026-10871
7.2 HIGHA vulnerability has been found in Shibby Tomato 1.28.0000
Published: 2026-06-04 · Last updated: 2026-06-05
Severity and scoring
- CVSS
- 7.2 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-77, CWE-78
Description
A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the component Web UI. Such manipulation of the argument ipv6_6rd_borderrelay leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This project is superseded by FreshTomato.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-10871
- [Other]https://gitee.com/WH-YHUST/tomato-rc-nvram-cve/blob/master/gitee-cve-disclosure/advisories/en/02-start_6rd_tunnel.md
- [Other]https://gitee.com/WH-YHUST/tomato-rc-nvram-cve/blob/master/gitee-cve-disclosure/advisories/zh/02-start_6rd_tunnel.md
- [Other]https://vuldb.com/cve/CVE-2026-10871
- [Other]https://vuldb.com/submit/831857
- [Other]https://vuldb.com/vuln/368361
- [Other]https://vuldb.com/vuln/368361/cti
Related CVEs
Same CWE
- CVE-2026-42846 — ClipBucket v5 is an open source video sharing platform (9.8 CRITICAL)
- CVE-2026-45172 — Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0....
- CVE-2026-48547 — KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands ... (7.3 HIGH)
- CVE-2026-49261 — MariaDB server is a community developed fork of MySQL server (10.0 CRITICAL)
- CVE-2026-49219 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.5 MEDIUM)