Shibby Tomato
- 1.28 RT-N5x MIPSR2 build 132 Max
A stack-based buffer overflow vulnerability has been identified in Shibby Tomato firmware versions prior to 1.28.0000. This issue arises in the DNS list rendering function 'sub_407220' within the 'httpd' component, located at '/usr/sbin/httpd'. The vulnerability can be exploited remotely by manipulating the size of the DNS list being processed.
Exploitation of this vulnerability can lead to a crash of the 'httpd' management service. Additionally, under certain memory conditions, it may allow for a stack overwrite that could corrupt saved registers or adjacent stack data.
The vulnerability can be reproduced by uploading a crafted DNS configuration that includes eight ordinary DNS entries. This can be done through the router's web interface or by directly modifying the router's DNS settings via a script or tool that interfaces with the router's firmware. Once the DNS entries are set, accessing the DNS list rendering feature will trigger the buffer overflow, as the 'httpd' service attempts to process the oversized DNS list without proper bounds checking.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.