VYPR
High severity8.8NVD Advisory· Published May 29, 2026· Updated May 29, 2026

CVE-2026-10065

CVE-2026-10065

Description

A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument Date can lead to stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack-based buffer overflow in Shibby Tomato 1.28 tomatodata.cgi via the Date argument allows remote attackers to execute arbitrary code.

Vulnerability

A stack-based buffer overflow vulnerability exists in Shibby Tomato firmware version 1.28. The flaw resides in the function get_ups_field within the file tomatodata.cgi. By manipulating the Date argument, an attacker can trigger a buffer overflow on the stack. This project is superseded by FreshTomato and is no longer supported by the maintainer. The vulnerability affects only the unsupported Shibby Tomato 1.28 release [1].

Exploitation

An attacker can exploit this vulnerability remotely without requiring authentication. The attack vector involves sending a crafted HTTP request to the tomatodata.cgi endpoint with an overly long Date parameter. The lack of proper bounds checking in get_ups_field allows the attacker-supplied data to overflow the stack buffer, potentially overwriting critical control flow data [1].

Impact

Successful exploitation leads to arbitrary code execution on the affected device. The attacker gains full control over the router's operating system, enabling actions such as installing malware, exfiltrating data, or pivoting to internal networks. The impact is high due to the remote, unauthenticated nature of the attack and the privileged context of the CGI process [1].

Mitigation

No official patch is available as Shibby Tomato 1.28 is end-of-life and no longer supported. Users are strongly advised to upgrade to FreshTomato, the actively maintained fork, which is not affected by this vulnerability. There are no known workarounds for the vulnerable firmware. This CVE is not listed in CISA's Known Exploited Vulnerabilities catalog as of the publication date [1].

AI Insight generated on May 29, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.