PT-2026-60934 · Unknown · Shibby Tomato
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Shibby Tomato version 1.28
Description
A stack-based buffer overflow exists in the Scheduler Name Handler component. The issue occurs within the
sub 42537C() function when the a1 argument is manipulated, allowing a remote authenticated attacker with admin-panel access to corrupt the stack and potentially execute arbitrary code on the router.Recommendations
Migrate to FreshTomato.
Restrict access to the router admin interface.
Fix
Buffer Overflow
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Shibby Tomato