Raspap
Vendor:
First CVE: Aug 24, 2020 · Active for 5 years
12
Total CVEs
More Total CVEs than 91% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 77% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Raspap over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2020
5 years ago
Most Recent CVE
Mar 15, 2024
865 days ago
CVE Severity & Scoring
Raspap12 CVEs
8%
75%
17%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (91.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (8.3%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (58.3%)
High1 (8.3%)
None4 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39986CRITICAL A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpnc | Aug 1, 2023 | 9.8 | 91 | NO | YES |
CVE-2021-33357CRITICAL A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as | Jun 9, 2021 | 9.8 | 51 | NO | YES |
CVE-2022-39987HIGH A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entity" POST parameters in /ajax/net | Aug 1, 2023 | 8.8 | 45 | NO | NO |
CVE-2021-38556HIGH includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection. | Aug 24, 2021 | 8.8 | 32 | NO | NO |
CVE-2020-24572HIGH An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unrestricted) web console to attack | Aug 24, 2020 | 8.8 | 29 | NO | NO |
CVE-2021-33356HIGH Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component th | Jun 9, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-38557HIGH raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablel | Aug 24, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-33358HIGH Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in /hostapd, when the parameter values contain special charact | Jun 9, 2021 | 8.8 | 26 | NO | NO |
CVE-2023-30260HIGH Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request to hostapd settings form. | Jun 23, 2023 | 8.8 | 24 | NO | NO |
CVE-2024-2497HIGH A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/provider.php of the component HT | Mar 15, 2024 | 7.2 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
8.3% of CVEs· 97th percentile
Nuclei
2 CVEs
16.7% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Raspap
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.9 | 1 | 7.2 | 0.9% | 0 | 0 |
| 2.6.6 | 2 | 8.8 | 7.6% | 0 | 0 |
| 2.5 | 1 | 8.8 | 6.8% | 0 | 0 |