Impact
Shibby Tomato firmware version 1.28 RT‑N5x MIPSR2 Build 124 contains a stack‑based buffer overflow in the function sub_40BB50 of /proc/webmon_recent_domains. The flaw is triggered by carefully crafted input data and allows an attacker to overwrite return addresses on the stack, leading to remote code execution. The vulnerability is catalogued as a high severity issue with a CVSS score of 8.7 and is classified under CWE-119 and CWE-121. Because the exploit can be launched remotely, an attacker could gain arbitrary code execution on the vulnerable device without local access.
Affected Systems
This vulnerability specifically affects Shibby Tomato 1.28 RT‑N5x MIPSR2 Build 124, an embedded router firmware. The affected component is the web monitoring recent domains handler located in /proc/webmon_recent_domains. The product has been superseded by FreshTomato, but devices still running the original firmware remain at risk. No other versions are listed as vulnerable in the provided data.
Risk and Exploitability
The EPSS score for this flaw is listed as <1 %, indicating that the probability of the vulnerability being exploited in the general population is currently very low, and the flaw is not included in CISA’s KEV catalogue. Nevertheless, the high CVSS score reflects the severity of the potential impact. An attacker with network access to the device can send a crafted request to the /proc/webmon_recent_domains endpoint, triggering the buffer overflow and achieving arbitrary code execution. Based on the description, it is inferred that exploitation requires only remote connectivity and no authentication, making it a significant threat to unprotected installations.
OpenCVE Enrichment