Unrated severityNVD Advisory· Published Jul 18, 2026· Updated Jul 20, 2026
Shibby Tomato rc setup_conntrack out-of-bounds write
CVE-2026-16095
Description
A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write. The attack may be performed from remote. This project is superseded by FreshTomato.
Affected products
1- Range: 1.28 RT-N5x MIPSR2 Build 124
Patches
Vulnerability mechanics
References
5- vuldb.com/cve/CVE-2026-16095mitrethird-party-advisory
- vuldb.com/submit/855123mitrethird-party-advisory
- gitee.com/Fengyi-Wang/CVE/issues/IJTQ5Smitreissue-tracking
- vuldb.com/vuln/379799mitrevdb-entrytechnical-description
- vuldb.com/vuln/379799/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.