Fruitywifi Project's vulnerability footprint centers on its wireless penetration-testing and network-auditing tool, with durable signal in the application's web-based management interface and authentication boundaries. The recurring weakness classes—OS command injection, cross-site request forgery, improper authentication, and improper privilege management—reflect the attack surface of a tool designed to interact with network devices and configurations. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fruitywifi Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19168CRITICAL Shell Metacharacter Injection in www/modules/save.php in FruityWifi (aka PatatasFritas/PatataWifi) through 2.4 allows remote attackers to execute arbitrary code with root privilege | Nov 11, 2018 | 9.8 | 33 | NO | NO |
CVE-2018-17317CRITICAL FruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the io_mode, ap_mode, io_action, io_in_iface, io_in_ | Sep 21, 2018 | 9.8 | 32 | NO | NO |
CVE-2020-24849HIGH A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST request at the page_config_adv. | Nov 5, 2020 | 8.8 | 28 | NO | NO |
CVE-2020-24848HIGH FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local privilege escalation, allowing a | Oct 23, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-24847MEDIUM A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php, an unauthenticated attacker can | Oct 23, 2020 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fruitywifi Project.
Media articles that mention a CVE ID that affects a product developed by Fruitywifi Project — matched by CVE ID, not by vendor name.