ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-3991
An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3.

An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

NVD description · AI analysis pending
9.82%
  • freshtomato freshtomato
CVE-2022-42484
+1 in the same advisory: …38451
An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5.

An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

NVD description · AI analysis pending
9.8
group max
6% PoC
  • freshtomato freshtomato
  • freshtomato quartz-gold firmware
CVE-2022-28664
+1 in the same advisory: …28665
A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1.

A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-mips` has a vulnerable URL-decoding feature that can lead to memory corruption.

NVD description · AI analysis pending
9.81% PoC
  • freshtomato freshtomato