Executive brief
A security flaw exists in the Shibby Tomato router firmware, which is used to manage home and small office network hardware. An attacker with administrative access to the router's web interface or command line can inject malicious commands that run with the highest system privileges (root). This could allow an attacker to establish a permanent backdoor on the device that survives reboots, potentially leading to full control over network traffic and connected devices.
Technical details
An OS command injection vulnerability exists in the start_jffs2 function (sub_2D568) within the sbin/rc binary of Shibby Tomato firmware. The vulnerability is caused by the direct passing of the 'jffs2_exec' NVRAM variable to the system() C library function without any sanitization or escaping. An attacker with the ability to modify NVRAM (typically requiring authenticated access to the Web UI or SSH) can inject shell metacharacters into this variable. The injected commands are executed with root privileges during the JFFS2 partition startup sequence, which occurs during boot or when the service is manually started. While Shibby Tomato is no longer maintained and has been superseded by FreshTomato, this specific flaw provides a mechanism for persistent code execution.
Affected products
- Shibby Tomato up to 1.28.0000
Timeline
- 2026-05-02: other: Vulnerability discovered via static analysis
- 2026-06-10: disclosed: Issue reported on Gitee repository
- 2026-07-13: advisory: CVE published by VulDB/NVD