Vulnerabilities
5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-3991 | An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2022-42484 +1 in the same advisory: …38451 | An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability. NVD description · AI analysis pending | 9.8 group max | 6% | PoC |
| — | |
| CVE-2022-28664 +1 in the same advisory: …28665 | A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-mips` has a vulnerable URL-decoding feature that can lead to memory corruption. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — |