Critical severity9.8NVD Advisory· Published Aug 27, 2025· Updated Jun 17, 2026
CVE-2025-50428
CVE-2025-50428
Description
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3<=3.3.2+ 2 more
- (no CPE)range: <=3.3.2
- cpe:2.3:a:raspap:raspap-webgui:*:*:*:*:*:*:*:*range: <=3.3.2
- (no CPE)
Patches
Vulnerability mechanics
References
2- github.com/RaspAP/raspap-webgui/pull/1833nvdIssue TrackingPatch
- blog.smarttecs.com/posts/2025-004-cve-2025-50428/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.