CVE-2026-10124

HIGH

Shibby Tomato Zserv ripd rip_zebra_read_ipv4 stack-based overflow

Title source: cna
STIX 2.1

Description

A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.

References (4)

Core 4
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-367301 | Shibby Tomato Zserv ripd rip_zebra_read_ipv4 stack-based overflow
https://vuldb.com/vuln/367301
Signature, Permissions Required signature permissions-required
VDB-367301 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/367301/cti
Third Party Advisory third-party-advisory
Submit #818239 | Tomato by Shibby Tomato Firmware 1.28 Stack-based Buffer Overflow
https://vuldb.com/submit/818239
Exploit exploit issue-tracking
https://gitee.com/Fengyi-Wang/CVE/issues/IJ9FFG

Scores

CVSS v3 8.8
EPSS 0.0047
EPSS Percentile 37.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-121
Status published
Products (29)
Shibby/Tomato 1.0
Shibby/Tomato 1.1
Shibby/Tomato 1.10
Shibby/Tomato 1.11
Shibby/Tomato 1.12
Shibby/Tomato 1.13
Shibby/Tomato 1.14
Shibby/Tomato 1.15
Shibby/Tomato 1.16
Shibby/Tomato 1.17
... and 19 more
Published May 30, 2026
Tracked Since May 30, 2026