Shibby Tomato
- >= 1.28.0000, <= 1.28.0000-120 K26ARM USB AIO-64K
A command injection vulnerability has been identified in the Shibby Tomato firmware versions up to 1.28.0000. The issue arises in the 'start_jffs2' function of the 'sbin/rc' component, where the NVRAM key 'jffs2_exec' is accessed without proper sanitization. This flaw allows remote exploitation, with injected commands executed as root during the JFFS2 initialization process. The vulnerability can be exploited by manipulating NVRAM values, a capability available through the web interface or other vulnerabilities.
Exploitation of this vulnerability leads to unauthorized command execution with root privileges, creating a persistent backdoor, as NVRAM values remain intact after a reboot.
The vulnerability can be reproduced by setting the NVRAM key 'jffs2_exec' with a command payload, enabling JFFS2 execution, and then manually starting the JFFS2 service or rebooting the device. This can be automated with a script that simulates the NVRAM manipulation and service initiation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.