SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-16095

HIGH · CVSS 8.8 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-07-18 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

A vulnerability exists in the Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124 firmware, specifically in the setup_conntrack function, which allows for an out-of-bounds write due to improper handling of the ct_tcp_timeout argument. This flaw can be exploited remotely, potentially leading to unauthorized access or system instability. Users and administrators of affected devices should prioritize patching or migrating to FreshTomato to mitigate the risk.

CVE
CVE-2026-16095
Severity
HIGH
CVSS
8.8
EPSS
0.42%

Original NVD Description

A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write. The attack may be performed from remote. This project is superseded by FreshTomato.