Executive brief
A security vulnerability exists in the Shibby Tomato firmware, which is used in various network routers. An attacker can exploit this flaw to crash the router or potentially take control of the device by sending a specially crafted response from a power supply (UPS) monitoring service. This product is no longer supported by the developer, and users are encouraged to migrate to newer alternatives like FreshTomato.
Technical details
A stack-based buffer overflow (CWE-121) exists in the get_ups_field function within tomatodata.cgi of Shibby Tomato firmware version 1.28. The vulnerability is triggered when the CGI component processes UPS (Uninterruptible Power Supply) information. Specifically, the function performs an unbounded byte-copy of the 'DATE' field into a fixed-size 256-byte stack buffer without verifying the length against the provided buffer size. An attacker who can control the response from a UPS server (e.g., via a man-in-the-middle or a malicious UPS host) can provide a 'DATE' field exceeding 256 bytes to overwrite stack memory. This can lead to process crashes or remote code execution. The project is end-of-life and has been superseded by FreshTomato.
Affected products
- Shibby Tomato by Shibby 1.28
Timeline
- 2026-05-02: disclosed: Initial vulnerability report by Fengyi Wang
- 2026-05-29: advisory: CVE published via VulDB/NVD