Shibby Tomato
- >= 1.28.0000, <= 1.28.0000-120 K26ARM USB AIO-64K
A stack-based buffer overflow vulnerability has been identified in Shibby Tomato firmware versions through 1.28.0000. The issue resides in the apcupsd component, specifically within the CGI programs tomatodata.cgi, tomatoups.cgi, and multimon.cgi. The vulnerability is triggered by the getupsvar function, which improperly handles input from the apcupsd daemon, leading to a buffer overflow that can be exploited remotely.
Exploitation of this vulnerability causes a denial-of-service condition by crashing the affected program. However, the nature of the buffer overflow also allows for potential remote code execution.
The vulnerability can be reproduced by starting a fake apcupsd server that responds with overly long field values. This server can be set up to pad responses with additional bytes, which will then be processed by the vulnerable CGI scripts. When the tomatodata.cgi script is executed, the unbounded input from the server is written into stack buffers, overflowing them and demonstrating the vulnerability. The same exploitation technique can be applied to the multimon.cgi and tomatoups.cgi scripts, with similar results.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.