Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-28151 represents a critical vulnerability in Tonda versions below 2.6, enabling unauthenticated attackers to perform Local File Inclusion (LFI) attacks without authentication. This CWE-98 vulnerability is particularly dangerous because it requires no prior access or credentials, allowing threat actors to read arbitrary files from the affected system—potentially exposing sensitive configuration files, credentials, source code, and other confidential data. Organizations deploying Tonda in production environments face immediate risk, as the vulnerability's CVSS score of 8.1 indicates high severity with significant impact on confidentiality and availability.
While this specific CVE currently maps to zero Casky.ai skills due to its emerging nature, practitioners should monitor Casky's Claude-powered reasoning engine as new skill mappings are developed. LFI attacks typically correlate with techniques like T1005 (Data from Local System), T1083 (File and Directory Discovery), and T1087 (Account Discovery)—patterns that Casky's extended reasoning can identify through behavioral analysis of file access requests, path traversal attempts, and unusual directory enumeration. As security teams investigate Tonda deployments, they should look for HTTP requests containing suspicious file path patterns (../../../../etc/passwd variants), failed authentication followed by file read attempts, and unexpected file access logs—indicators that Casky's skill framework will help surface once LFI-specific patterns are integrated into the platform.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-28151. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation