SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-16096

HIGH · CVSS 8.8 EPSS 0.44%

Source: NVD + CISA KEV + EPSS · Published 2026-07-18 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

A stack-based buffer overflow vulnerability in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124 allows remote attackers to manipulate the function sub_40BB50 within the /proc/webmon_recent_domains file. Successful exploitation could lead to arbitrary code execution, posing a significant risk to affected systems. Users and administrators of this firmware should prioritize patching or migrating to FreshTomato to mitigate potential threats.

CVE
CVE-2026-16096
Severity
HIGH
CVSS
8.8
EPSS
0.44%

Original NVD Description

A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This project is superseded by FreshTomato.