CVE-2026-10066
Description
A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component UPS Service. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stack-based buffer overflow in Shibby Tomato up to 1.28's tomatoups.cgi allows remote unauthenticated attackers to execute arbitrary code.
Vulnerability
The UPS Service component in Shibby Tomato firmware up to version 1.28 contains a stack-based buffer overflow vulnerability in the sub_9068 function of the tomatoups.cgi file [1]. The vulnerability is reached via the web interface without requiring authentication, making it remotely exploitable. The product is end-of-life and superseded by FreshTomato; no fixed version is available from the original maintainer [1].
Exploitation
An attacker can send a crafted HTTP request to the vulnerable CGI endpoint, triggering a stack buffer overflow in the sub_9068 function. No authentication is required; the attack vector is network-based [1]. The exploit does not require user interaction and can be executed remotely over the network.
Impact
Successful exploitation leads to arbitrary code execution with the privileges of the web server (typically root on embedded devices). This allows the attacker to gain full control of the affected device, enabling information disclosure, installation of persistent backdoors, or further network compromise [1].
Mitigation
No official fix exists as Shibby Tomato 1.28 is end-of-life and no longer supported by the maintainer [1]. Users are strongly advised to upgrade to FreshTomato, the actively maintained fork, to mitigate this vulnerability. There is no evidence that this CVE is listed in CISA's Known Exploited Vulnerabilities catalog.
AI Insight generated on May 29, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.