Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Raspap

First CVE: Aug 24, 2020Active for: 6 yearsTotal CVEs: 15
63.5
VTI Score
TOP TARGET

Raspap is a lightweight web-based management interface for Raspberry Pi wireless networking configurations, presenting a focused but prominently deployed attack surface in small-network and IoT administration tools. Vulnerabilities affecting this product skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by recurring command and code injection weaknesses that arise from insufficient input sanitization and privilege-management gaps in web request handling. Defenders should prioritize patching this component when exposed to untrusted networks; live exploitation activity and current severity counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
8.6
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Raspap over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2020
5 years ago
Most Recent CVE
Aug 27, 2025
331 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-39986CRITICAL
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpnc
Aug 1, 20239.891NOYES
CVE-2021-33357CRITICAL
A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as
Jun 9, 20219.851NOYES
CVE-2022-39987HIGH
A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entity" POST parameters in /ajax/net
Aug 1, 20238.845NONO
CVE-2025-50428CRITICAL
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user inpu
Aug 27, 20259.834NONO
CVE-2021-38556HIGH
includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.
Aug 24, 20218.832NONO
CVE-2020-24572HIGH
An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unrestricted) web console to attack
Aug 24, 20208.829NONO
CVE-2024-36622CRITICAL
In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input pass
Nov 29, 20249.827NONO
CVE-2021-33356HIGH
Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component th
Jun 9, 20218.827NONO
CVE-2021-38557HIGH
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablel
Aug 24, 20218.826NONO
CVE-2021-33358HIGH
Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in /hostapd, when the parameter values contain special charact
Jun 9, 20218.826NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
13%
60%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (93.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (6.7%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (93.3%)
Unknown0 (0.0%)
Required1 (6.7%)
Privileges Required
Low7 (46.7%)
High1 (6.7%)
None7 (46.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
6.7% of CVEs· 98th percentile
Nuclei
2 CVEs
13.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Raspap.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Raspap — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Raspap's Products

View all 2 CNAs →

Top CWEs