Vulnerabilities > Raspap > Raspap > 2.0

DATE CVE VULNERABILITY TITLE RISK
2023-06-23 CVE-2023-30260 Command Injection vulnerability in Raspap
Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request to hostapd settings form.
network
low complexity
raspap CWE-77
8.8
2021-06-09 CVE-2021-33356 Improper Privilege Management vulnerability in Raspap
Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component that can result in remote command execution with root privileges.
network
low complexity
raspap CWE-269
8.8