VYPR

RaspAP

by RaspAP

Source repositories

CVEs (12)

  • CVE-2022-39986CriAug 1, 2023
    risk 0.68cvss 9.8epss 0.99

    A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.

  • CVE-2021-33357CriJun 9, 2021
    risk 0.65cvss 9.8epss 0.17

    A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as ";" which enables an unauthenticated attacker to execute arbitrary OS commands.

  • CVE-2021-38556HigAug 24, 2021
    risk 0.58cvss 8.8epss 0.13

    includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.

  • CVE-2021-33356HigJun 9, 2021
    risk 0.58cvss 8.8epss 0.05

    Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component that can result in remote command execution with root privileges.

  • CVE-2021-38557HigAug 24, 2021
    risk 0.57cvss 8.8epss 0.02

    raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data account can also overwrite…

  • CVE-2021-33358HigJun 9, 2021
    risk 0.57cvss 8.8epss 0.03

    Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in /hostapd, when the parameter values contain special characters such as ";" or "$()" which enables an authenticated attacker to execute arbitrary OS commands.

  • CVE-2022-39987HigAug 1, 2023
    risk 0.53cvss 8.8epss 0.39

    A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entity" POST parameters in /ajax/networking/get_wgkey.php.

  • CVE-2023-30260HigJun 23, 2023
    risk 0.50cvss 8.8epss 0.02

    Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request to hostapd settings form.

  • CVE-2024-28754HigMar 9, 2024
    risk 0.42cvss 7.5epss 0.01

    RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to cause a persistent denial of service (bricking) via a crafted request.

  • CVE-2024-28753MedMar 9, 2024
    risk 0.42cvss 6.5epss 0.01

    RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to read the /etc/passwd file via a crafted request.

  • CVE-2024-2497MedMar 15, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/provider.php of the component HTTP POST Request Handler. The manipulation of the argument country leads to code injection. The…

  • CVE-2020-24572HigAug 24, 2020
    risk 0.01cvss 8.8epss 0.07

    An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unrestricted) web console to attack the underlying OS (Raspberry Pi) running this software, and execute commands on the system…