CVE-2021-33357
raspap raspap Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2021-33357 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as ";" which enables an unauthenticated attacker to execute arbitrary OS commands.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 21, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
raspapBrowse raspap / raspap | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALRaspAP <=2.6.5 - Remote Command InjectionCVSS 9.8
RaspAP 2.6 to 2.6.5 allows unauthenticated attackers to execute arbitrary OS commands via the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as ";".
Impact
Successful exploitation of this vulnerability can lead to unauthorized remote code execution, compromising the integrity and confidentiality of the affected system.
Remediation
Upgrade RaspAP to a version higher than 2.6.5 to mitigate the vulnerability.
Source: ProjectDiscovery