Description
A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call Handler. This manipulation causes server-side request forgery. The attack may be initiated remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer.
Problem types
Product status
Timeline
| 2026-05-29: | Advisory disclosed |
| 2026-05-29: | VulDB entry created |
| 2026-05-29: | VulDB entry last update |
Credits
VulDB Gitee Analyzer
VulDB CNA Team
References
gitee.com/Fengyi-Wang/CVE/issues/IJD8SS
vuldb.com/vuln/367154 (VDB-367154 | Shibby Tomato SUBSCRIBE Call miniupnpd send server-side request forgery)
vuldb.com/vuln/367154/cti (VDB-367154 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/submit/818237 (Submit #818237 | Tomato by Shibby Tomato Firmware 1.28 Out-of-Bounds Read)
gitee.com/Fengyi-Wang/CVE/issues/IJD8SS