fig. 01 — GHSA-wqhw-frpx-5mmp, the advisory selected below
// advisories
GHSA-wqhw-frpx-5mmp
HIGH
All versions of tomato are vulnerable to Command Injection. The /api/exec endpoint does not validate user input allowing attackers to run arbitrary commands in the system.