Raspap

Raspap-webgui

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.06%
  • Veröffentlicht 29.09.2026 02:16:54
  • Zuletzt bearbeitet 29.09.2026 18:57:24

A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. This manipulation of the argument ssid cau...

  • EPSS 1.58%
  • Veröffentlicht 29.09.2026 02:16:54
  • Zuletzt bearbeitet 01.10.2026 16:17:32

A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escapeshellcmd of the file ajax/openvpn/del_ovpncfg.php of the component OpenVPN Configuration Handler. Such manipulation of the argume...

  • EPSS 0.47%
  • Veröffentlicht 29.09.2026 02:16:54
  • Zuletzt bearbeitet 29.09.2026 18:57:24

A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation result...

  • EPSS 1.33%
  • Veröffentlicht 02.02.2026 04:37:03
  • Zuletzt bearbeitet 15.04.2026 00:35:42

RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product.

Exploit
  • EPSS 1.63%
  • Veröffentlicht 27.08.2025 17:15:41
  • Zuletzt bearbeitet 09.09.2025 18:45:52

In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.

Exploit
  • EPSS 0.6%
  • Veröffentlicht 27.06.2025 00:00:00
  • Zuletzt bearbeitet 10.11.2025 20:38:28

RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable ...

  • EPSS 2.76%
  • Veröffentlicht 29.11.2024 18:15:08
  • Zuletzt bearbeitet 02.07.2025 20:41:55

In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.