Vulnerabilidades en FreshTomato
5 resultadosAnálisis Vexday
FreshTomato apresenta 5 vulnerabilidades catalogadas, com 2 classificadas como críticas, sendo injeção de comando (CWE-78) o padrão dominante. Não há evidência de exploração ativa em campo (KEV) e nenhuma vulnerabilidade foi divulgada nos últimos 90 dias, indicando um risco presente mas não de resposta imediata.
CVE-2022-42484CRITICALAn OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP requesEPSS 6.0%CVE-2023-3991CRITICALOS command injection vulnerability in FreshTomato 2023.3EPSS 2.4%CVE-2022-38451MEDIUMA directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request canEPSS 2.1%CVE-2022-28664MEDIUMA memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can leaEPSS 1.4%CVE-2022-28665MEDIUMA memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can leaEPSS 1.3%