CVE-2026-19035

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-06 12:16

Updated : 2026-08-12 21:00


NVD link : CVE-2026-19035

Mitre link : CVE-2026-19035

CVE.ORG link : CVE-2026-19035


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')