CVE-2026-10872

Severity CVSS v4.0:
HIGH
Type:
CWE-77 Command Injection
Publication date:
04/06/2026
Last modified:
22/07/2026

Description

A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. Performing a manipulation results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. This project is superseded by FreshTomato.