Tomato by Shibby OS Command Injection Vulnerability in JFFS2 Startup Function

Vulnerability

A command injection vulnerability has been identified in the Shibby Tomato firmware versions up to 1.28.0000. The issue arises in the 'start_jffs2' function of the 'sbin/rc' component, where the NVRAM key 'jffs2_exec' is accessed without proper sanitization. This flaw allows remote exploitation, with injected commands executed as root during the JFFS2 initialization process. The vulnerability can be exploited by manipulating NVRAM values, a capability available through the web interface or other vulnerabilities.

Impact

Exploitation of this vulnerability leads to unauthorized command execution with root privileges, creating a persistent backdoor, as NVRAM values remain intact after a reboot.

Reproduction

The vulnerability can be reproduced by setting the NVRAM key 'jffs2_exec' with a command payload, enabling JFFS2 execution, and then manually starting the JFFS2 service or rebooting the device. This can be automated with a script that simulates the NVRAM manipulation and service initiation.

Added: Jul 13, 2026, 9:29 AM
Updated: Jul 13, 2026, 9:29 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.1
remediation
0.0
relevance
9.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.