PT-2026-44887 · Unknown · Shibby Tomato

Fengyi Wang

·

Published

2026-05-29

·

Updated

2026-05-29

·

CVE-2026-10068

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Shibby Tomato version 1.28
Description A flaw in the SUBSCRIBE Call Handler component allows for server-side request forgery, a condition where an attacker can induce the server to make requests to an unintended location. The issue is located in the send() function within the usr/sbin/miniupnpd file and can be triggered remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-10068

Affected Products

Shibby Tomato