Lucene search

K

FreshTomato Security Vulnerabilities

cve
cve

CVE-2023-3991

An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this...

10CVSS

9.6AI Score

0.002EPSS

2023-10-16 10:15 AM
10
cve
cve

CVE-2022-42484

An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this...

9.8CVSS

9.7AI Score

0.007EPSS

2023-01-30 11:15 AM
21
cve
cve

CVE-2022-38451

A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this...

7.5CVSS

8.6AI Score

0.004EPSS

2023-01-30 11:15 AM
11
cve
cve

CVE-2022-28664

A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The freshtomato-mips has a vulnerable URL-decoding feature that...

9.8CVSS

9.5AI Score

0.008EPSS

2022-08-05 10:15 PM
62
7
cve
cve

CVE-2022-28665

A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The freshtomato-arm has a vulnerable URL-decoding feature that...

9.8CVSS

9.5AI Score

0.009EPSS

2022-08-05 10:15 PM
61
7