CVE-2024-36622 is a critical command injection vulnerability affecting RaspAP webgui versions 3.0.9 and earlier, stemming from insufficient sanitization of the 'logfile' parameter in the clearlog.php script. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to execute arbitrary commands remotely, leading to complete compromise of confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or active exploitation have been observed, its high severity and ease of exploitation warrant immediate attention. Community discussion and media coverage for this CVE are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0.9CPE matchmatch criteria | cpe:2.3:a:raspap:raspap-webgui:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.