FreshtomatoCVEs & Vulnerabilities

5 CVEs affecting Freshtomato products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

freshtomato 5
CVE-2023-3991CRITICAL

An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

16 Oct 2023
9.8
CVSS
CVE-2022-42484CRITICAL

An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

30 Jan 2023
9.8
CVSS
CVE-2022-38451HIGH

A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

30 Jan 2023
7.5
CVSS
CVE-2022-28665CRITICAL

A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-arm` has a vulnerable URL-decoding feature that can lead to memory corruption.

6 Aug 2022
9.8
CVSS
CVE-2022-28664CRITICAL

A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-mips` has a vulnerable URL-decoding feature that can lead to memory corruption.

6 Aug 2022
9.8
CVSS
← PrevPage 1 / 1Next →
Freshtomato CVEs & Vulnerabilities — 5 Tracked