Unrated severityNVD Advisory· Published Jun 9, 2021· Updated Aug 3, 2024
CVE-2021-33358
CVE-2021-33358
Description
Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in /hostapd, when the parameter values contain special characters such as ";" or "$()" which enables an authenticated attacker to execute arbitrary OS commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- RaspAP/RaspAPdescription
Patches
Vulnerability mechanics
References
3- gist.github.com/omriinbar/52c000c02a6992c6ce68d531195f69cfmitrex_refsource_MISC
- github.com/RaspAP/raspap-webgui/blob/8f0ae3b36aa1020d21477e66010c6b2146e7c222/app/img/wifi-qr-code.phpmitrex_refsource_MISC
- github.com/RaspAP/raspap-webgui/blob/b02660d5ff8d9faa5d3ef49778b23e832851e0f4/includes/hostapd.phpmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.