Executive brief
A vulnerability exists in the Shibby Tomato router firmware that allows an administrator to execute arbitrary system commands with root privileges. By entering specially crafted text into the DHCP custom settings field, an attacker can take full control of the device's operating system. This could lead to complete network compromise, data interception, or the use of the router as a foothold for further attacks.
Technical details
The vulnerability is located in the start_dhcpc function within /sbin/rc. The firmware retrieves the 'dhcpc_custom' NVRAM key and uses strcpy/strcat to copy it into a 256-byte stack buffer (dest) without bounds checking, leading to a stack-based buffer overflow (CWE-121). Subsequently, this unsanitized input is formatted into a command string via snprintf and executed using _xstart("/bin/sh", "-c", dest), resulting in OS command injection (CWE-78). An authenticated attacker with web administrative access can trigger this by injecting shell metacharacters (e.g., semicolons) into the DHCP custom parameters field. The exploit is persistent as the injected payload is written back to NVRAM. This project is superseded by FreshTomato.
Affected products
- Tomato Firmware Tomato by Shibby (RAF lineage) 1.28.0000 MIPSR2-124 K26 USB Big-VPN
Timeline
- 2026-05-17: disclosed: Initial researcher disclosure on Gitee
- 2026-06-04: advisory: CVE-2026-10870 published
References
- https://gitee.com/WH-YHUST/tomato-rc-nvram-cve/blob/master/gitee-cve-disclosure/advisories/en/01-start_dhcpc.md
- https://gitee.com/WH-YHUST/tomato-rc-nvram-cve/blob/master/gitee-cve-disclosure/advisories/zh/01-start_dhcpc.md
- https://vuldb.com/cve/CVE-2026-10870
- https://vuldb.com/submit/831856
- https://vuldb.com/vuln/368360
- https://vuldb.com/vuln/368360/cti