CVE-2026-101858
- EPSS 2.06%
- Veröffentlicht 29.09.2026 02:16:54
- Zuletzt bearbeitet 29.09.2026 18:57:24
A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. This manipulation of the argument ssid cau...
CVE-2026-101859
- EPSS 1.58%
- Veröffentlicht 29.09.2026 02:16:54
- Zuletzt bearbeitet 01.10.2026 16:17:32
A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escapeshellcmd of the file ajax/openvpn/del_ovpncfg.php of the component OpenVPN Configuration Handler. Such manipulation of the argume...
- EPSS 0.47%
- Veröffentlicht 29.09.2026 02:16:54
- Zuletzt bearbeitet 29.09.2026 18:57:24
A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation result...
CVE-2026-24788
- EPSS 1.33%
- Veröffentlicht 02.02.2026 04:37:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product.
CVE-2025-50428
- EPSS 1.63%
- Veröffentlicht 27.08.2025 17:15:41
- Zuletzt bearbeitet 09.09.2025 18:45:52
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.
CVE-2025-44163
- EPSS 0.6%
- Veröffentlicht 27.06.2025 00:00:00
- Zuletzt bearbeitet 10.11.2025 20:38:28
RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable ...
CVE-2024-36622
- EPSS 2.76%
- Veröffentlicht 29.11.2024 18:15:08
- Zuletzt bearbeitet 02.07.2025 20:41:55
In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.