CVE-2026-10872 OS Command Injection in Shibby Tomato 1.28.0000. Remote exploitation via Web UI. CVSS 7.2. No patch available. Upgrade to FreshTomato immediately. #CVE#infosec#shibby
A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. Perform...