Impact
A stack‑based buffer overflow exists in the getupsvar function of tomatodata.cgi, triggered by manipulating the Field argument. This flaw is identified as CWE‑119 and CWE‑121. If successfully exploited, it could allow remote attackers to crash the service or potentially execute arbitrary code on the device. The vulnerability is remote‑initiated, has been publicly disclosed, and may be utilized.
Affected Systems
Shibby Tomato devices running version 1.28.0000 or older, specifically the apcupsd component exposed at www/apcupsd/tomatodata.cgi, are affected.
Risk and Exploitability
The CVSS score of 8.7 denotes high severity. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote; a public exploit has been disclosed, but real‑world exploitation remains unlikely at present.
OpenCVE Enrichment