CVE-2026-10124: Stack-based Buffer Overflow in Shibby Tomato
A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.
AI Analysis
Technical Summary
This vulnerability involves a stack-based buffer overflow in the rip_zebra_read_ipv4 function within the ripd daemon's Zserv Handler component of Shibby Tomato firmware up to version 1.28. An attacker can remotely trigger this overflow by sending manipulated input, potentially leading to code execution or denial of service. The vulnerability has a CVSS 4.0 base score of 8.7, indicating high severity with network attack vector, low complexity, no user interaction, and high impacts on confidentiality, integrity, and availability. The affected product is no longer maintained, and no official remediation or patch is available.
Potential Impact
Successful exploitation can lead to remote code execution or denial of service due to a stack-based buffer overflow in the ripd daemon. The vulnerability impacts confidentiality, integrity, and availability of the affected device. Since the affected Shibby Tomato versions are no longer supported, users remain exposed if they continue to use these versions. No known active exploitation has been reported.
Mitigation Recommendations
There is no official patch or remediation available for this vulnerability as the affected Shibby Tomato versions are no longer supported and the project has been superseded by FreshTomato. Users are advised to migrate to supported firmware such as FreshTomato to mitigate this risk. Patch status is not yet confirmed — check vendor advisories or project updates for any new remediation guidance.
CVE-2026-10124: Stack-based Buffer Overflow in Shibby Tomato
Description
A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS v4.0
Score 8.7high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves a stack-based buffer overflow in the rip_zebra_read_ipv4 function within the ripd daemon's Zserv Handler component of Shibby Tomato firmware up to version 1.28. An attacker can remotely trigger this overflow by sending manipulated input, potentially leading to code execution or denial of service. The vulnerability has a CVSS 4.0 base score of 8.7, indicating high severity with network attack vector, low complexity, no user interaction, and high impacts on confidentiality, integrity, and availability. The affected product is no longer maintained, and no official remediation or patch is available.
Potential Impact
Successful exploitation can lead to remote code execution or denial of service due to a stack-based buffer overflow in the ripd daemon. The vulnerability impacts confidentiality, integrity, and availability of the affected device. Since the affected Shibby Tomato versions are no longer supported, users remain exposed if they continue to use these versions. No known active exploitation has been reported.
Mitigation Recommendations
There is no official patch or remediation available for this vulnerability as the affected Shibby Tomato versions are no longer supported and the project has been superseded by FreshTomato. Users are advised to migrate to supported firmware such as FreshTomato to mitigate this risk. Patch status is not yet confirmed — check vendor advisories or project updates for any new remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-05-29T17:21:10.262Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a1b06d4e29bf47b50425a43
Added to database: 05/30/2026, 15:48:36 UTC
Last enriched: 06/06/2026, 20:57:35 UTC
Last updated: 07/31/2026, 19:22:57 UTC
Views: 91
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.