← Back to browse · API

CVE-2023-3991

Severity
CRITICAL
CVSS
10.0
EPSS
0.02431
Risk score
40.85
CISA KEV
No
PoC
No
Published
2023-10-16
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2023-44614, GHSA-G95V-666P-2M3X
Products
FreshTomato:FreshTomato 2023.3
Sources
euvd EUVD-2023-44614

Description

An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

References