Tomato by Shibby Stack-Based Buffer Overflow Vulnerability in apcupsd CGI Programs

Vulnerability

A stack-based buffer overflow vulnerability has been identified in Shibby Tomato firmware versions through 1.28.0000. The issue resides in the apcupsd component, specifically within the CGI programs tomatodata.cgi, tomatoups.cgi, and multimon.cgi. The vulnerability is triggered by the getupsvar function, which improperly handles input from the apcupsd daemon, leading to a buffer overflow that can be exploited remotely.

Impact

Exploitation of this vulnerability causes a denial-of-service condition by crashing the affected program. However, the nature of the buffer overflow also allows for potential remote code execution.

Reproduction

The vulnerability can be reproduced by starting a fake apcupsd server that responds with overly long field values. This server can be set up to pad responses with additional bytes, which will then be processed by the vulnerable CGI scripts. When the tomatodata.cgi script is executed, the unbounded input from the server is written into stack buffers, overflowing them and demonstrating the vulnerability. The same exploitation technique can be applied to the multimon.cgi and tomatoups.cgi scripts, with similar results.

Added: Jul 13, 2026, 8:26 AM
Updated: Jul 13, 2026, 8:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.2
remediation
0.0
relevance
9.7
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.