Executive brief
A security vulnerability exists in the Shibby Tomato router firmware, which is used to manage home and small office network routers. An attacker who can influence the DNS configuration can cause the router's management web service to crash or potentially take control of the device. This could lead to a complete loss of internet connectivity or unauthorized access to the network's administrative interface.
Technical details
A stack-based buffer overflow exists in the 'httpd' binary of Shibby Tomato firmware (up to version 1.28.0000) within the DNS List Rendering component. The vulnerability is located in function 'sub_407220', where the software allocates a fixed 128-byte stack buffer to store a JavaScript array of DNS server information. The function uses 'sprintf' in a loop to append DNS entries without performing bounds checking. If the number of DNS entries (retrieved via 'get_dns()') is sufficiently large (e.g., 8 or more entries), the resulting string exceeds the 128-byte buffer, leading to a stack overflow. This can be exploited by an authenticated attacker to crash the management service or potentially achieve remote code execution. The Shibby Tomato project is superseded by FreshTomato.
Affected products
- Shibby Tomato up to 1.28.0000
Timeline
- 2026-06-10: disclosed: Initial discovery and report by Fengyi Wang
- 2026-07-13: advisory: CVE published by VulDB/NVD