Vulnerabilities (CVE)

Filtered by vendor Raspap Subscribe
Filtered by product Raspap
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-39986 1 Raspap 1 Raspap 2023-08-15 N/A 9.8 CRITICAL
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.
CVE-2021-33357 1 Raspap 1 Raspap 2021-06-21 7.5 HIGH 9.8 CRITICAL
A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as ";" which enables an unauthenticated attacker to execute arbitrary OS commands.