Tomato
This hub aggregates every CVE we track for Tomato, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
OSS Librariesother
23
CVEs tracked
0
Critical
20
High
0
In CISA KEV
Severity distribution
HIGH20MEDIUM3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
6
4
8
3
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Tomato.
- CVE-2026-19036Shibby Tomato wanoptions sub_40F88C os command injection7.2
- CVE-2026-19035Shibby Tomato qoslimit new_qoslimit_start os command injection7.2
- CVE-2026-19034Shibby Tomato qoslimittc_stop.sh new_qoslimit_stop os command injection7.2
- CVE-2026-16097Shibby Tomato Scheduler Name sub_42537C stack-based overflow8.8
- CVE-2026-16096Shibby Tomato webmon_recent_domains sub_40BB50 stack-based overflow8.8
- CVE-2026-16095Shibby Tomato rc setup_conntrack out-of-bounds write8.8
- CVE-2026-15548Shibby Tomato DNS List Rendering httpd sub_407220 stack-based overflow8.8
- CVE-2026-15547Shibby Tomato CIFS Mount sub_2D048 os command injection6.3
- CVE-2026-15546Shibby Tomato start_jffs2 sub_2D568 os command injection6.3
- CVE-2026-15545Shibby Tomato apcupsd tomatodata.cgi main out-of-bounds write8.8
- CVE-2026-15544Shibby Tomato apcupsd tomatodata.cgi getupsvar stack-based overflow8.8
- CVE-2026-10873Shibby Tomato Web UI rstats rstats_path os command injection7.2
- CVE-2026-10872Shibby Tomato Web UI rc start_vpnserver os command injection7.2
- CVE-2026-10871Shibby Tomato Web UI rc start_6rd_tunnel os command injection7.2
- CVE-2026-10870Shibby Tomato Web UI rc start_dhcpc os command injection7.2
Product normalization is registry-driven with AI assist and human review. How it works