Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Embedthis

First CVE: Mar 31, 2015Active for: 11 yearsTotal CVEs: 25
68.2
VTI Score
TOP TARGET

Embedthis maintains a narrow but strategically positioned product line centered on lightweight embedded web servers and application frameworks, particularly GoAhead and AppWeb, that are deployed across networked appliances, IoT devices, and edge systems where footprint and resource constraints drive adoption. Vulnerabilities affecting this vendor skew strongly toward critical severity and frequently acquire public exploit code, reflecting both the memory-safety challenges of embedded C codebases and the high value of compromising internet-facing appliances. The exposure recurs through a durable set of weakness classes—NULL-pointer dereferences, authentication bypasses via capture-replay, improper access control, code injection, and information disclosure—that together characterize the authentication and input-handling demands of embedded web interfaces. Because these products are often compiled into firmware and deployed across long product lifecycles with infrequent patching, a single vulnerability can remain exploitable across millions of installed devices for years. Defenders should prioritize inventory of Embedthis-based appliances, restrict management exposure, and treat this vendor's security advisories as high-impact despite the modest product count; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
4.0%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Embedthis over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 31, 2015
11 years ago
Most Recent CVE
Oct 17, 2024
645 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-17562HIGH
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. This is a result of initializing the environment of forked CG
Dec 12, 20178.198YESYES
CVE-2019-5096CRITICAL
An exploitable code execution vulnerability exists in the processing of multi-part/form-data requests within the base GoAhead web server application in versions v5.0.1, v.4.1.1 and
Dec 3, 20199.868NONO
CVE-2021-42342CRITICAL
An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts without being prefixed with the CGI prefix.
Oct 14, 20219.863NONO
CVE-2018-8715HIGH
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible
Mar 15, 20188.149NOYES
CVE-2019-5097HIGH
A denial-of-service vulnerability exists in the processing of multi-part/form-data requests in the base GoAhead web server application in versions v5.0.1, v.4.1.1 and v3.6.5. A spe
Dec 3, 20197.548NONO
CVE-2017-5674CRITICAL
A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.i
Mar 13, 20179.842NONO
CVE-2014-9708MEDIUM
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demons
Mar 31, 20155.042NONO
CVE-2014-9707HIGH
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a
Mar 31, 20157.542NOYES
CVE-2019-16645HIGH
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary H
Sep 20, 20198.641NOYES
CVE-2017-1000471CRITICAL
EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service.
Jan 3, 20189.832NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
20%
56%
24%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (92.0%)
Unknown2 (8.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (72.0%)
High5 (20.0%)
Unknown2 (8.0%)
User Interaction
None22 (88.0%)
Unknown2 (8.0%)
Required1 (4.0%)
Privileges Required
Low3 (12.0%)
High0 (0.0%)
None20 (80.0%)
Unknown2 (8.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
1 CVE
4.0% of CVEs· 99th percentile
Metasploit
2 CVEs
8.0% of CVEs· 98th percentile
Nuclei
2 CVEs
8.0% of CVEs· 96th percentile
ExploitDB
2 CVEs
8.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Embedthis.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Embedthis — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Embedthis's Products

View all 4 CNAs →

Top CWEs