CVE-2026-16097 HIGH

CVE-2026-16097: Shibby Tomato Scheduler Name sub_42537C stack-based overflow

Vendor Shibby
Product Tomato
Weakness CWE-121
Published July 18, 2026
Last update July 20, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X

What the vulnerability does

01Description

A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato.

Key dates

02Disclosure timeline

July 18, 2026 CVE published
July 20, 2026 Record updated