Shibby Tomato
- >= 1.28.0000, <= 1.28.0000-120 K26ARM USB AIO-64K
A vulnerability allowing an out-of-bounds write has been identified in Shibby Tomato firmware versions through 1.28.0000. The issue resides in the apcupsd component, specifically within the CGI programs tomatodata.cgi, tomatoups.cgi, and multimon.cgi. The vulnerability is triggered by the main function's parsing of the multimon.conf configuration file, leading to stack corruption that could be exploited remotely. This vulnerability is publicly known and has an available exploit.
Exploitation of this vulnerability causes a stack corruption, leading to a process crash. However, the corruption can be manipulated to alter saved registers and return addresses, potentially allowing for control-flow hijacking.
The vulnerability can be reproduced by creating a multimon.conf file with controlled line lengths, particularly one that exceeds the buffer size of the adjacent stack variable. This file must be placed in a directory that the apcupsd CGI programs can access. The CGI program can then be executed under QEMU user-mode ARM emulation, with the configuration file being parsed by the vulnerable program. The stack corruption can be verified using GDB, which will show the altered return address and confirm the crash.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.