Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-16096: Shibby Tomato 1.28 Router Configuration Data Exposure

CVE-2026-16096
Summary

A security flaw in Shibby Tomato 1.28 allows hackers to access sensitive router configuration data remotely. This can lead to unauthorized changes to the router settings. We recommend updating to a newer version of Shibby Tomato or switching to a more secure alternative, such as FreshTomato.

Original title
A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buf...
Original description
A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This project is superseded by FreshTomato.
nvd CVSS2.0 9.0
nvd CVSS3.1 8.8
nvd CVSS4.0 8.7
Vulnerability type
CWE-119 Buffer Overflow
CWE-121 Stack-based Buffer Overflow
Published: 18 Jul 2026 · Updated: 19 Jul 2026 · First seen: 18 Jul 2026