Impact
An out-of-bounds write flaw exists in the main function of www/apcupsd/tomatodata.cgi in Shibby Tomato up to version 1.28.0000. The defect is a classic buffer overflow (CWE‑119) and out-of-bounds write (CWE‑787) that can corrupt memory. Manipulation of the CGI inputs triggers this overflow, which might result in crashes or unintended behavior.
Affected Systems
The flaw affects Shibby Tomato appliances running any version up to and including 1.28.0000. The vulnerable component is the apcupsd plugin in the Tomato web interface. Versions newer than 1.28.0000 have not been reported as affected; however, the description specifies "up to 1.28.0000," implying all releases in that range remain vulnerable.
Risk and Exploitability
The CVSS score of 8.7 categorizes this issue as High severity. The EPSS score is <1%, indicating a very low probability of exploitation, although the CVE notes that a public exploit is already in circulation and may be employed by attackers. The attack may be launched remotely. The award vector is remote, likely via crafted HTTP requests to /apcupsd/tomatodata.cgi; this inference is based on the vulnerability description. The vulnerability is not listed in the CISA KEV catalog, yet the presence of a public exploit indicates a tangible risk to affected deployments.
OpenCVE Enrichment