Executive brief
A vulnerability exists in the Shibby Tomato and Tomato PL firmware, which are used to manage various home and small office routers. The flaw is located in the system's task scheduler, which handles automated background operations. An attacker could exploit this to crash the router or potentially take full control of the device, leading to data interception or network disruption.
Technical details
A stack-based buffer overflow and OS command injection vulnerability exists in the 'sbin/rc' component of Tomato firmware, specifically within the 'sub_42537C' function called by 'sched_main'. The vulnerability is caused by the unsafe use of 'sprintf' to format a 64-byte stack buffer with an attacker-controlled scheduler name argument ('a1'). Because the scheduler name is inserted into the command string multiple times without length validation or shell escaping, an attacker can overflow the buffer to overwrite the saved return address or inject shell metacharacters into a subsequent 'system()' call. While default initialization uses safe, fixed names, the vulnerability is reachable if an attacker can influence the scheduler name via authenticated web or API interfaces. This project is superseded by FreshTomato.
Affected products
- Shibby Tomato 1.28
- MariuszNM Tomato PL ND 1.28 beta
Timeline
- 2026-06-10: disclosed: Initial report by Fengyi Wang via Gitee
- 2026-07-18: advisory: NVD/VulDB publication