CVE-2026-10873
Shibby Tomato
A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats of the component Web UI. Executing a manipulation can lead to os command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato.
- CVSS
- 7.3
- EPSS
- 2.70% 84.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.05