CVE-2026-10067
Description
A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A stack-based buffer overflow in Shibby Tomato 1.28's multimon.cgi allows remote attackers to execute arbitrary code on unsupported devices.
Vulnerability
A stack-based buffer overflow vulnerability exists in the sub_90F0 function of the multimon.cgi CGI script in Shibby Tomato firmware version 1.28. The flaw is triggered by manipulating input data, leading to memory corruption. This version is no longer supported, and the project has been superseded by FreshTomato [1].
Exploitation
An attacker can exploit this vulnerability remotely without requiring authentication. By sending a specially crafted HTTP request to the multimon.cgi endpoint, the attacker can overflow a stack buffer, potentially overwriting critical data or control flow structures. No user interaction is needed beyond the target device being reachable over the network [1].
Impact
Successful exploitation allows an attacker to achieve arbitrary code execution on the affected device. Given that Shibby Tomato is a router firmware, this could lead to full compromise of the device, including network traffic interception, configuration changes, and further lateral movement within the network [1].
Mitigation
No official patch is available from Shibby as the project is end-of-life. The only recommended mitigation is to upgrade to FreshTomato, the actively maintained successor. Users should also consider replacing unsupported hardware. This vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the publication date [1].
AI Insight generated on May 29, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.