Freshtomato is a firmware distribution for consumer networking devices, with its vulnerability footprint centered on OS command injection, out-of-bounds writes, and path-traversal weaknesses typical of embedded systems with complex CLI and file-handling interfaces. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freshtomato over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-42484CRITICAL An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command executio | Jan 30, 2023 | 9.8 | 33 | NO | NO |
CVE-2022-28665CRITICAL A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can | Aug 5, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-28664CRITICAL A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can | Aug 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-3991CRITICAL An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially crafted HTTP request can lead to arbitrary command execution | Oct 16, 2023 | 9.8 | 27 | NO | NO |
CVE-2022-38451HIGH A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary file read. An attacke | Jan 30, 2023 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freshtomato.
Media articles that mention a CVE ID that affects a product developed by Freshtomato — matched by CVE ID, not by vendor name.