VYPR
High severity8.8NVD Advisory· Published May 29, 2026· Updated May 29, 2026

CVE-2026-10066

CVE-2026-10066

Description

A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component UPS Service. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A stack-based buffer overflow in Shibby Tomato up to 1.28's tomatoups.cgi allows remote unauthenticated attackers to execute arbitrary code.

Vulnerability

The UPS Service component in Shibby Tomato firmware up to version 1.28 contains a stack-based buffer overflow vulnerability in the sub_9068 function of the tomatoups.cgi file [1]. The vulnerability is reached via the web interface without requiring authentication, making it remotely exploitable. The product is end-of-life and superseded by FreshTomato; no fixed version is available from the original maintainer [1].

Exploitation

An attacker can send a crafted HTTP request to the vulnerable CGI endpoint, triggering a stack buffer overflow in the sub_9068 function. No authentication is required; the attack vector is network-based [1]. The exploit does not require user interaction and can be executed remotely over the network.

Impact

Successful exploitation leads to arbitrary code execution with the privileges of the web server (typically root on embedded devices). This allows the attacker to gain full control of the affected device, enabling information disclosure, installation of persistent backdoors, or further network compromise [1].

Mitigation

No official fix exists as Shibby Tomato 1.28 is end-of-life and no longer supported by the maintainer [1]. Users are strongly advised to upgrade to FreshTomato, the actively maintained fork, to mitigate this vulnerability. There is no evidence that this CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

AI Insight generated on May 29, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.