CVE-2026-10872 OS Command Injection in Shibby Tomato 1.28.0000. Remote exploitation via Web UI. CVSS 7.2. No patch available. Upgrade to FreshTomato immediately. #CVE #infosec #shibby

https://www.valtersit.com/cve/CVE-2026-10872/

CVE-2026-10872 | Shibby | Valters IT Hub

A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. Perform...

Valters IT Hub