Total
3 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-44163 | 1 Raspap | 1 Raspap-webgui | 2025-11-10 | N/A | 6.3 MEDIUM |
| RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable by the web server via abuse of the `tee` command used in shell execution. | |||||
| CVE-2025-50428 | 1 Raspap | 1 Raspap-webgui | 2025-09-09 | N/A | 9.8 CRITICAL |
| In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter. | |||||
| CVE-2024-36622 | 1 Raspap | 1 Raspap-webgui | 2025-07-02 | N/A | 9.8 CRITICAL |
| In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter. | |||||
