SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-15545

HIGH · CVSS 8.8 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The vulnerability in Shibby Tomato versions up to 1.28.0000 affects the `main` function in the `www/apcupsd/tomatodata.cgi` file, allowing for an out-of-bounds write that can be exploited remotely. This poses a significant risk as it could lead to unauthorized access or system compromise. Users of Shibby Tomato, particularly those managing critical network devices, should prioritize patching or migrating to FreshTomato to mitigate this threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15545
Severity
HIGH
CVSS
8.8
EPSS
0.40%

Original NVD Description

A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of the file www/apcupsd/tomatodata.cgi of the component apcupsd. Such manipulation leads to out-of-bounds write. The attack may be launched remotely. The exploit is publicly available and might be used. This project is superseded by FreshTomato.