Siretta develops a focused line of cellular gateway and modem products, primarily the Quartz Gold family, that serve as network access points in remote and industrial deployments. The vendor's vulnerability footprint, while concentrated in a small product portfolio, skews strongly toward critical-severity outcomes across a set of low-level defects characteristic of embedded networking firmware: buffer overflows, out-of-bounds writes, OS command injection, path traversal, and active debug code that expose the devices to remote compromise and privilege escalation. The severity profile reflects the memory-unsafe implementation common to embedded systems and the direct internet or network exposure typical of gateway devices, which present high-value targets for reconnaissance and persistent access. Defenders should prioritize inventory and patching of Quartz Gold deployments, particularly in operational-technology and remote-access contexts where replacement cycles may be extended. Current exploitation activity, KEV listing status, and public-exploit availability are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Siretta over time
Signals from CVEs in this vendor scope (64 CVEs).
64 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-42484CRITICAL An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command executio | Jan 30, 2023 | 9.8 | 33 | NO | NO |
CVE-2022-41004CRITICAL Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network | Jan 26, 2023 | 9.8 | 32 | NO | NO |
CVE-2022-41000CRITICAL Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network | Jan 26, 2023 | 9.8 | 32 | NO | NO |
CVE-2022-42493CRITICAL Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary comman | Jan 26, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-42491CRITICAL Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary comman | Jan 26, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-42490CRITICAL Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary comman | Jan 26, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-41991CRITICAL A heap-based buffer overflow vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can le | Jan 26, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-41018CRITICAL Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network | Jan 26, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-41016CRITICAL Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network | Jan 26, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-41008CRITICAL Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network | Jan 26, 2023 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (64 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Siretta.
Media articles that mention a CVE ID that affects a product developed by Siretta — matched by CVE ID, not by vendor name.