VYPR
High severity8.8NVD Advisory· Published May 30, 2026

CVE-2026-10124

CVE-2026-10124

Description

A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stack-based buffer overflow in Shibby Tomato's ripd Zserv handler allows remote attackers to execute arbitrary code on unsupported firmware.

Vulnerability

A stack-based buffer overflow exists in the function rip_zebra_read_ipv4 within the file /usr/sbin/ripd of Shibby Tomato firmware up to version 1.28. The vulnerability resides in the Zserv Handler component, which processes incoming routing protocol messages. The overflow occurs when handling specially crafted IPv4 data, leading to memory corruption. Affected versions include all releases up to and including 1.28. This project is superseded by FreshTomato and is no longer supported by the maintainer [1].

Exploitation

An attacker can exploit this vulnerability remotely without requiring authentication. By sending a maliciously crafted packet to the RIP daemon (ripd), the attacker triggers a stack-based buffer overflow. The exploit has been publicly disclosed, providing a proof-of-concept that demonstrates the attack sequence [1]. No user interaction or special network position beyond reachability of the RIP service is needed.

Impact

Successful exploitation allows the attacker to achieve arbitrary code execution on the target device. Since ripd typically runs with root privileges, the attacker gains full control over the router, enabling data exfiltration, further network compromise, or persistent backdoor installation. The impact is critical for any organization still using the unsupported Shibby Tomato firmware.

Mitigation

No official patch is available from the maintainer, as Shibby Tomato is end-of-life and no longer supported. Users must upgrade to FreshTomato, the actively maintained fork, which is not affected by this vulnerability. There is no workaround that fully mitigates the risk while running the vulnerable firmware. This vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 30, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.