← Back

Raspap Webgui

raspap-webgui

Vendor: Raspap • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Raspap
1Raspap Webgui
Sep 9, 2025
Aug 27, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.
1Raspap
1Raspap Webgui
Nov 10, 2025
Jun 27, 2025
N/A· v4
6.3 MEDIUM· v3
N/A· v2
RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overw...Show more
RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable by the web server via abuse of the `tee` command used in shell execution.Show less
1Raspap
1Raspap Webgui
Jul 2, 2025
Nov 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.