Impact
Being a stack-based buffer overflow in the sub_42537C function of Shibby Tomato 1.28, this vulnerability allows an attacker who supplies a crafted a1 argument to corrupt the stack and execute arbitrary code. The corruption can jeopardize the confidentiality, integrity, and availability of the affected system. The flaw is a classic buffer overflow (CWE-119) that is exploitable remotely, meaning an attacker need not be physically present.
Affected Systems
The only publicly listed affected product is Shibby Tomato, version 1.28. No other products or versions are mentioned in the advisory, and the project has been superseded by FreshTomato.
Risk and Exploitability
The vulnerability scores a CVSS of 8.7, indicating high severity, but its EPSS is less than 1 %, suggesting a low current chance of exploitation. It is not listed in the CISA KEV catalog. Because the flaw is remote‑able and can lead to code execution, the risk remains significant until mitigated. The attack likely proceeds by feeding a specially crafted input into the Scheduler Name Handler over the network, leveraging the stack corruption to jump to attacker‑controlled code.
OpenCVE Enrichment