Raspap is a lightweight web-based management interface for Raspberry Pi wireless networking configurations, presenting a focused but prominently deployed attack surface in small-network and IoT administration tools. Vulnerabilities affecting this product skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by recurring command and code injection weaknesses that arise from insufficient input sanitization and privilege-management gaps in web request handling. Defenders should prioritize patching this component when exposed to untrusted networks; live exploitation activity and current severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Raspap over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39986CRITICAL A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpnc | Aug 1, 2023 | 9.8 | 91 | NO | YES |
CVE-2021-33357CRITICAL A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as | Jun 9, 2021 | 9.8 | 51 | NO | YES |
CVE-2022-39987HIGH A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entity" POST parameters in /ajax/net | Aug 1, 2023 | 8.8 | 45 | NO | NO |
CVE-2025-50428CRITICAL In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user inpu | Aug 27, 2025 | 9.8 | 34 | NO | NO |
CVE-2021-38556HIGH includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection. | Aug 24, 2021 | 8.8 | 32 | NO | NO |
CVE-2020-24572HIGH An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unrestricted) web console to attack | Aug 24, 2020 | 8.8 | 29 | NO | NO |
CVE-2024-36622CRITICAL In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input pass | Nov 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2021-33356HIGH Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component th | Jun 9, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-38557HIGH raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablel | Aug 24, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-33358HIGH Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in /hostapd, when the parameter values contain special charact | Jun 9, 2021 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Raspap.
Media articles that mention a CVE ID that affects a product developed by Raspap — matched by CVE ID, not by vendor name.