Shibby Tomato Stack-Based Buffer Overflow Vulnerability in DNS List Rendering

Vulnerability

A stack-based buffer overflow vulnerability has been identified in Shibby Tomato firmware versions prior to 1.28.0000. This issue arises in the DNS list rendering function 'sub_407220' within the 'httpd' component, located at '/usr/sbin/httpd'. The vulnerability can be exploited remotely by manipulating the size of the DNS list being processed.

Impact

Exploitation of this vulnerability can lead to a crash of the 'httpd' management service. Additionally, under certain memory conditions, it may allow for a stack overwrite that could corrupt saved registers or adjacent stack data.

Reproduction

The vulnerability can be reproduced by uploading a crafted DNS configuration that includes eight ordinary DNS entries. This can be done through the router's web interface or by directly modifying the router's DNS settings via a script or tool that interfaces with the router's firmware. Once the DNS entries are set, accessing the DNS list rendering feature will trigger the buffer overflow, as the 'httpd' service attempts to process the oversized DNS list without proper bounds checking.

Added: Jul 13, 2026, 12:15 PM
Updated: Jul 13, 2026, 12:15 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
8.7
remediation
0.0
relevance
9.3
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.