Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-16096: Shibby Tomato 1.28 Router Configuration Data Exposure
CVE-2026-16096
Summary
A security flaw in Shibby Tomato 1.28 allows hackers to access sensitive router configuration data remotely. This can lead to unauthorized changes to the router settings. We recommend updating to a newer version of Shibby Tomato or switching to a more secure alternative, such as FreshTomato.
Original title
A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buf...
Original description
A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This project is superseded by FreshTomato.
nvd CVSS2.0
9.0
nvd CVSS3.1
8.8
nvd CVSS4.0
8.7
Vulnerability type
CWE-119
Buffer Overflow
CWE-121
Stack-based Buffer Overflow
Published: 18 Jul 2026 · Updated: 19 Jul 2026 · First seen: 18 Jul 2026