medium · CVSS v3 4.7 · CVSS v4 5.1
CVE-2026-101858
A remote OS command injection flaw exists in RaspAP raspap-webgui versions up to 3.5.5, allowing attackers to execute arbitrary commands via
Overview
A remote OS command injection flaw exists in RaspAP raspap-webgui versions up to 3.5.5, allowing attackers to execute arbitrary commands via the SSID field. The vulnerability is triggered by manipulating the ssid argument in WiFiManager::writeWpaSupplicant. It can be exploited without authentication, potentially compromising the underlying system.
Description
A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. This manipulation of the argument ssid causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
Confidentiality: attackers can read sensitive system files. Integrity: they can modify or delete configuration files. Availability: they can disrupt network services. The flaw affects devices running the vulnerable RaspAP web interface, such as home routers and IoT gateways.
Remediation
Upgrade RaspAP raspap-webgui to version 3.5.6 or later where the input is sanitized. If upgrade is not possible, disable remote access to the web interface or restrict it to trusted IPs. Additionally, apply a firewall rule to block outbound connections to the wpa_supplicant command or use SELinux/AppArmor to confine the web server process.
Risk context
Severity is medium (CVSS 4.7/5.1). No EPSS data available. The vulnerability is publicly known and exploitable remotely, so defenders should prioritize remediation.
Affected products
- RaspAP raspap-webgui 3.5.5 and earlier
Scores
- Severity
- medium
- CVSS v2
- 5.8
- CVSS v3
- 4.7
- CVSS v4
- 5.1
- EPSS
- —