Products

Showing 6 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
raspap vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

RaspAP raspap-webgui contains an OS Command Injection vulnerability

RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product.

CWE-78Feb 2, 2026
CVSS8.7v4.0EPSS1.33%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

RaspAP allows an attacker to escalate privileges

RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo privileges to execute several critical commands without a password.

CWE-269CWE-77Jul 29, 2024
CVSS-v4.0EPSS0.81%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

RaspAP raspap-webgui HTTP POST Request provider.php code injection

A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/provider.php of the component HTTP POST Request Handler. The manipulation of the argument country leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256919. NOTE: The vendor was contacted early about this disclosure but did

CWE-94Mar 15, 2024
CVSS4.7v3.1EPSS0.907%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

raspap-webgui vulnerable to denial of service

RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to cause a persistent denial of service (bricking) via a crafted request.

Mar 8, 2024
CVSS-v4.0EPSS0.856%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

RaspAP Command Injection vulnerability

A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.

CWE-77Aug 1, 20231 related artifact
CVSS9.8v3.1EPSS99%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

raspap raspap Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as ";" which enables an unauthenticated attacker to execute arbitrary OS commands.

CWE-78Jun 9, 20211 related artifact
CVSS9.8v3.1EPSS17.4%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX