Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 29 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of the component SUBSCRIBE Call Handler. This manipulation causes server-side request forgery. The attack may be initiated remotely. This project is superseded by FreshTomato. This vulnerability only affects products that are no longer supported by the maintainer. | |
| Title | Shibby Tomato SUBSCRIBE Call miniupnpd send server-side request forgery | |
| First Time appeared |
Shibby
Shibby tomato |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:shibby:tomato:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Shibby
Shibby tomato |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-29T17:11:09.721Z
Reserved: 2026-05-29T08:32:34.889Z
Link: CVE-2026-10068
Updated: 2026-05-29T17:10:39.714Z
Status : Deferred
Published: 2026-05-29T16:16:23.750
Modified: 2026-05-29T18:16:30.663
Link: CVE-2026-10068
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:18:32Z