← Browse

CVE-2026-10871

Medium

Elevated severity or exploit probability.

CVSS base
7.2 HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
2.2%
81.7th percentile
CISA KEV
Not listed
Weakness / dates
CWE-77
Published 2026-06-04 · modified 2026-07-22

Description

A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the component Web UI. Such manipulation of the argument ipv6_6rd_borderrelay leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This project is superseded by FreshTomato.

References

Official: NVD · CVE.org