Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Raspap Webgui CRITICAL 9.8
CVE-2025-50428

In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to i…

Fix: after 3.3.2
Fix from $2,300 2025-08-27
Raspap Webgui MEDIUM 6.3
CVE-2025-44163

RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST r…

No fix yet
Fix from $1,600 2025-06-27
Raspap Webgui CRITICAL 9.8
CVE-2024-36622

In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper …

Fix: after 3.0.9
Fix from $2,300 2024-11-29
Raspap HIGH 7.2
CVE-2024-2497

A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/p…

No fix yet
Fix from $1,950 2024-03-15
Raspap HIGH 7.5
CVE-2024-28754

RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to cause a persistent denial of service (bricking) via a crafted request.

Fix: after 3.0.9
Fix from $1,950 2024-03-09
Raspap MEDIUM 6.5
CVE-2024-28753

RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to read the /etc/passwd file via a crafted request.

Fix: after 3.0.9
Fix from $1,600 2024-03-09
Raspap CRITICAL 9.8
CVE-2022-39986EPSS 99%

A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter …

Fix: after 2.8.7
Fix from $2,300 2023-08-01
Raspap HIGH 8.8
CVE-2022-39987EPSS 39%

A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entit…

Fix: after 2.9.2
Fix from $1,950 2023-08-01
Raspap HIGH 8.8
CVE-2023-30260

Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request …

Fix: after 2.8.8
Fix from $1,950 2023-06-23
Raspap HIGH 8.8
CVE-2021-38556EPSS 13%

includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.

No fix yet
Fix from $1,950 2021-08-24
Raspap HIGH 8.8
CVE-2021-38557

raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can exec…

No fix yet
Fix from $1,950 2021-08-24
Raspap CRITICAL 9.8
CVE-2021-33357EPSS 17%

A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value conta…

Fix: after 2.6.5
Fix from $2,300 2021-06-09
Raspap HIGH 8.8
CVE-2021-33356EPSS 5%

Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /in…

Fix: after 2.6.5
Fix from $1,950 2021-06-09
Raspap HIGH 8.8
CVE-2021-33358

Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in /hostapd, when the parameter…

Fix: after 2.6.5
Fix from $1,950 2021-06-09
Raspap HIGH 8.8
CVE-2020-24572EPSS 7%

An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unres…

Patch available
Fix from $1,950 2020-08-24