Cosori manufactures internet-connected kitchen appliances including air fryers, with known vulnerabilities concentrated in the CS158-AF product line and its firmware. The recurring exposure centers on memory-safety and logic-layer issues typical of embedded device firmware, including buffer overflows, out-of-bounds writes, and hidden functionality weaknesses. Current CVE counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cosori over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-28592CRITICAL A heap-based buffer overflow vulnerability exists in the configuration server functionality of the Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A specially crafted JSON object | Apr 15, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-28593HIGH A unauthenticated backdoor exists in the configuration server functionality of Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A specially crafted JSON object can lead to code exe | Apr 15, 2021 | 8.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cosori.
Media articles that mention a CVE ID that affects a product developed by Cosori — matched by CVE ID, not by vendor name.