Ucdok
Ucdok Tomato: vulnerabilidades y CVE
Ucdok Tomato tiene 22 vulnerabilidades publicadas, 21 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses21
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-19036 | Alta (7.3) | 3.2% | — | 6 ago 2026 | A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulation of the argument ppp_custom results in os command injection. The… |
| CVE-2026-19035 | Alta (7.3) | 3.2% | — | 6 ago 2026 | A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The manipulation of the argument new_qoslimit_enable leads to os command… |
| CVE-2026-19034 | Alta (7.3) | 3.2% | — | 6 ago 2026 | A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimittc_stop.sh. Executing a manipulation of the argument wan_iface can… |
| CVE-2026-16097 | Alta (8.7) | 0.79% | — | 18 jul 2026 | A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It… |
| CVE-2026-16096 | Alta (8.7) | 0.79% | — | 18 jul 2026 | A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is… |
| CVE-2026-16095 | Alta (8.7) | 0.73% | — | 18 jul 2026 | A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the argument ct_tcp_timeout can lead to… |
| CVE-2026-15548 | Alta (7.4) | 0.79% | — | 13 jul 2026 | A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub_407220 of the file /usr/sbin/httpd of the component DNS List Rendering. The manipulation leads to… |
| CVE-2026-15547 | Baja (2.1) | 1.8% | — | 13 jul 2026 | A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a manipulation of the argument cifs1/cifs2 can lead to os command… |
| CVE-2026-15546 | Baja (2.1) | 1.8% | — | 13 jul 2026 | A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 of the component start_jffs2. Performing a manipulation of the argument jffs2_exec results in os… |
| CVE-2026-15545 | Alta (7.4) | 0.73% | — | 13 jul 2026 | A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of the file www/apcupsd/tomatodata.cgi of the component apcupsd. Such manipulation leads to… |
| CVE-2026-15544 | Alta (7.4) | 0.79% | — | 13 jul 2026 | A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation of the argument Field causes… |
| CVE-2026-10873 | Alta (7.3) | 2.7% | — | 4 jun 2026 | A vulnerability was determined in Shibby Tomato 1.28.0000. Impacted is the function rstats_path of the file /bin/rstats of the component Web UI. Executing a manipulation can lead to os command injection. The attack can… |
| CVE-2026-10872 | Alta (7.3) | 2.6% | — | 4 jun 2026 | A vulnerability was found in Shibby Tomato 1.28.0000. This issue affects the function start_vpnserver of the file /sbin/rc of the component Web UI. Performing a manipulation results in os command injection. The attack… |
| CVE-2026-10871 | Alta (7.3) | 2.2% | — | 4 jun 2026 | A vulnerability has been found in Shibby Tomato 1.28.0000. This vulnerability affects the function start_6rd_tunnel of the file /sbin/rc of the component Web UI. Such manipulation of the argument ipv6_6rd_borderrelay… |
| CVE-2026-10870 | Alta (7.3) | 2.2% | — | 4 jun 2026 | A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the component Web UI. This manipulation causes os command injection. It is possible to initiate the attack… |
| CVE-2026-10124 | Alta (7.4) | 0.47% | — | 30 may 2026 | A vulnerability was determined in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer… |
| CVE-2026-10069 | Alta (8.7) | 0.44% | — | 29 may 2026 | A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/miniupnpd. Such manipulation leads to resource consumption. The attack may be launched remotely.… |
| CVE-2026-10068 | Media (6.9) | 0.28% | — | 29 may 2026 | A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call Handler. This manipulation causes server-side request forgery. The… |
| CVE-2026-10067 | Alta (8.7) | 0.44% | — | 29 may 2026 | A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. This project… |
| CVE-2026-10066 | Alta (8.7) | 0.44% | — | 29 may 2026 | A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the file tomatoups.cgi of the component UPS Service. The manipulation leads to stack-based buffer… |
| CVE-2026-10065 | Alta (8.7) | 0.44% | — | 29 may 2026 | A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file tomatodata.cgi. Executing a manipulation of the argument Date can lead to stack-based buffer… |
| CVE-2013-7379 | Media (6.8) | 2.5% | — | 16 may 2014 | The admin API in the tomato module before 0.0.6 for Node.js does not properly check the access key when it is set to a string, which allows remote attackers to bypass authentication via a string in the access-key header… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.