CVE-2026-10069
Description
A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/miniupnpd. Such manipulation leads to resource consumption. The attack may be launched remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Shibby Tomato 1.28's miniupnpd has an uncontrolled resource consumption vulnerability that an unauthenticated remote attacker can exploit to cause a denial of service.
Vulnerability
A resource consumption vulnerability exists in Shibby Tomato firmware version 1.28, specifically in the usr/sbin/miniupnpd binary. The unknown function within this component does not properly control the buffering of HTTP requests, allowing an attacker to exhaust system resources. This version is the last release of the Shibby Tomato project, which is superseded by FreshTomato and no longer supported [1].
Exploitation
The attack can be launched remotely without authentication. An attacker sends specially crafted HTTP requests to the UPnP service, causing the device to allocate excessive memory or CPU resources. The specific sequence of requests required to trigger the resource exhaustion is not detailed in the available reference, but the issue is classified as an uncontrolled resource consumption in HTTP request buffering [1].
Impact
Successful exploitation leads to uncontrolled resource consumption, resulting in a denial of service (DoS). The target device may become unresponsive or crash, impacting network availability. Since the attack is remote and requires no authentication, any affected device exposed to the network is at risk [1].
Mitigation
The Shibby Tomato 1.28 firmware is end-of-life (EOL) and no longer supported by its maintainer. No official patch will be released. Users are strongly advised to upgrade to a supported fork such as FreshTomato. No workaround is provided in the reference [1].
AI Insight generated on May 29, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.28
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.