Junglewise Threat Intelligence

CVE-2026-10873: Shibby Tomato OS command injection in rstats_path

CVE-2026-10873 · Severity: high · CVSS 7.2 · Published 2026-06-04

Technologies: Shibby Tomato. Vendors: Shibby.

Executive brief

A vulnerability exists in the Shibby Tomato router firmware, specifically within its bandwidth monitoring component. An attacker with administrative access can provide a specially crafted file path that allows them to execute unauthorized commands on the router's operating system. This could lead to a complete takeover of the device, potentially compromising the entire network it manages.

Technical details

An OS command injection vulnerability exists in the /bin/rstats binary of Shibby Tomato firmware version 1.28.0000. The rstats_path function retrieves the 'rstats_path' value from NVRAM and passes it to a system() call via sprintf without adequate shell metacharacter filtering. An attacker with Web UI administrative credentials can exploit this by navigating to Admin -> Bandwidth Monitoring and setting a custom 'f_user' path containing shell injectors (e.g., using semicolons or hash marks). The vulnerability is triggered when the rstats service restarts or processes the path. While Shibby Tomato is superseded by FreshTomato, which has hardened this component using zlib and snprintf, the original Shibby branch remains vulnerable.

Affected products

  • Shibby Tomato 1.28.0000 MIPSR2-124 K26 USB Big-VPN 1.28.0000

Timeline

  • 2026-05-17: disclosed: Initial disclosure by researcher WH-YHUST
  • 2026-06-04: advisory: NVD publication date

References

Related threats