Vulnerabilities (CVE)

Filtered by vendor Raspap Subscribe
Filtered by product Raspap-webgui
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-44163 1 Raspap 1 Raspap-webgui 2025-11-10 N/A 6.3 MEDIUM
RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable by the web server via abuse of the `tee` command used in shell execution.
CVE-2025-50428 1 Raspap 1 Raspap-webgui 2025-09-09 N/A 9.8 CRITICAL
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.
CVE-2024-36622 1 Raspap 1 Raspap-webgui 2025-07-02 N/A 9.8 CRITICAL
In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.