High severity8.8NVD Advisory· Published Jun 23, 2023· Updated Jun 17, 2026
CVE-2023-30260
CVE-2023-30260
Description
Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request to hostapd settings form.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
billz/raspap-webguiPackagist | < 2.8.9 | 2.8.9 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/RaspAP/raspap-webgui/pull/1322nvdPatchWEB
- eldstal.se/advisories/230328-raspap.htmlnvdExploitMitigationThird Party AdvisoryWEB
- github.com/advisories/GHSA-hhqm-f4m4-pq39ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-30260ghsaADVISORY
- github.com/RaspAP/raspap-webgui/commit/238e1670fcef8b18ec4628ee74fc345607536a16ghsaWEB
News mentions
0No linked articles in our index yet.