Raspap

Vendor:

First CVE: Aug 24, 2020 · Active for 5 years

12
Total CVEs
More Total CVEs than 91% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 77% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Raspap over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2020
5 years ago
Most Recent CVE
Mar 15, 2024
865 days ago

CVE Severity & Scoring

Raspap12 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (91.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (8.3%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (58.3%)
High1 (8.3%)
None4 (33.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpnc
Aug 1, 20239.891NOYES
A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as
Jun 9, 20219.851NOYES
A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entity" POST parameters in /ajax/net
Aug 1, 20238.845NONO
includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.
Aug 24, 20218.832NONO
An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unrestricted) web console to attack
Aug 24, 20208.829NONO
Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component th
Jun 9, 20218.827NONO
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablel
Aug 24, 20218.826NONO
Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in /hostapd, when the parameter values contain special charact
Jun 9, 20218.826NONO
Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request to hostapd settings form.
Jun 23, 20238.824NONO
A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/provider.php of the component HT
Mar 15, 20247.221NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
8.3% of CVEs· 97th percentile
Nuclei
2 CVEs
16.7% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Raspap

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.0.917.20.9%00
2.6.628.87.6%00
2.518.86.8%00