Filtered by vendor Raspap Subscriptions
Filtered by product Raspap-webgui Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-44163 1 Raspap 1 Raspap-webgui 2025-11-10 6.3 Medium
RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable by the web server via abuse of the `tee` command used in shell execution.
CVE-2025-50428 1 Raspap 1 Raspap-webgui 2025-09-09 9.8 Critical
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.
CVE-2024-36622 1 Raspap 1 Raspap-webgui 2025-07-02 9.8 Critical
In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.