Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-28152 represents a critical vulnerability in Tonda Core versions below 2.6, enabling unauthenticated attackers to perform Local File Inclusion (LFI) attacks. This CWE-98 vulnerability allows adversaries to access sensitive files on the affected system without requiring valid credentials, potentially exposing configuration files, source code, and other confidential data. Organizations running vulnerable Tonda Core instances face significant risk, as LFI can serve as a stepping stone for deeper system compromise, information gathering, and lateral movement within the infrastructure.
While this CVE currently maps to zero Casky.ai skills due to the absence of MITRE ATT&CK technique mappings, practitioners should leverage Claude AI's extended reasoning capabilities within Casky to identify the behavioral patterns associated with file inclusion attacks. Security teams would focus on detection patterns related to path traversal attempts, unusual file access requests, and parameter manipulation in web requests. By analyzing request patterns and system logs through Casky's AI-powered analysis, practitioners can identify reconnaissance activities (T1083: File and Directory Discovery) and initial access attempts (T1190: Exploit Public-Facing Application) that precede successful LFI exploitation, enabling earlier intervention before sensitive data exposure occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-28152. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation