Getcujo's vulnerability footprint centers on its Smart Firewall product, a network security appliance operating at the edge of home and small-business deployments. The disclosures skew strongly toward critical-severity outcomes and recur through command-injection and code-injection vulnerabilities characteristic of network appliances that parse and execute user-supplied input, along with memory-safety weaknesses such as double-free conditions that arise in embedded C codebases. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Getcujo over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-4003CRITICAL An exploitable heap overflow vulnerability exists in the mdnscap binary of the CUJO Smart Firewall running firmware 7003. The string lengths are handled incorrectly when parsing ch | Mar 21, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-4031CRITICAL An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsing function parses HTTP requests | Oct 31, 2019 | 10.0 | 30 | NO | NO |
CVE-2018-3985CRITICAL An exploitable double free vulnerability exists in the mdnscap binary of the CUJO Smart Firewall. When parsing mDNS packets, a memory space is freed twice if an invalid query name | Mar 21, 2019 | 9.8 | 29 | NO | NO |
CVE-2018-3963HIGH An exploitable command injection vulnerability exists in the DHCP daemon configuration of the CUJO Smart Firewall. When adding a new static DHCP address, its corresponding hostname | Mar 21, 2019 | 8.0 | 27 | NO | NO |
CVE-2018-4011HIGH An exploitable integer underflow vulnerability exists in the mdnscap binary of the CUJO Smart Firewall, version 7003. When parsing SRV records in an mDNS packet, the "RDLENGTH" val | Mar 21, 2019 | 7.5 | 24 | NO | NO |
CVE-2018-3969HIGH An exploitable vulnerability exists in the verified boot protection of the CUJO Smart Firewall. It is possible to add arbitrary shell commands into the dhcpd.conf file, that persis | Mar 21, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-4030HIGH An exploitable vulnerability exists the safe browsing function of the CUJO Smart Firewall, version 7003. The bug lies in the way the safe browsing function parses HTTP requests. Th | Mar 21, 2019 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Getcujo.
Media articles that mention a CVE ID that affects a product developed by Getcujo — matched by CVE ID, not by vendor name.