CVE-2026-10065 Details
Description
A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument Date can lead to stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.
A stack-based buffer overflow vulnerability has been identified in Shibby Tomato firmware version 1.28. The issue arises in the function get_ups_field within the file tomatodata.cgi, where the argument Date is manipulated, leading to a stack-based buffer overflow. This vulnerability can be exploited remotely and affects products that are no longer supported by the maintainer.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 29, 2026CISA-ADP
Assessed May 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitee.com/Fengyi-Wang/CVE/issues/IJK7BC | CISA-ADP | ExploitTechnical Analysis |
| https://vuldb.com/submit/818144 | CISA-ADP | Permission Required |
| https://gitee.com/Fengyi-Wang/CVE/issues/IJK7BC | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/submit/818144 | [email protected] | Permission Required |
| https://vuldb.com/vuln/367151 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/367151/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Shibby Tomato | Tomato v1.28.0000 -120 K26ARM USB AIO-64K |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | CVE Modified | CISA-ADP |
| May 29, 2026 | New CVE Received | [email protected] |
Volerion