rootpwn

medium · CVSS v3 4.7 · CVSS v4 5.1

CVE-2026-101858

A remote OS command injection flaw exists in RaspAP raspap-webgui versions up to 3.5.5, allowing attackers to execute arbitrary commands via

Overview

A remote OS command injection flaw exists in RaspAP raspap-webgui versions up to 3.5.5, allowing attackers to execute arbitrary commands via the SSID field. The vulnerability is triggered by manipulating the ssid argument in WiFiManager::writeWpaSupplicant. It can be exploited without authentication, potentially compromising the underlying system.

Description

A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. This manipulation of the argument ssid causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

Confidentiality: attackers can read sensitive system files. Integrity: they can modify or delete configuration files. Availability: they can disrupt network services. The flaw affects devices running the vulnerable RaspAP web interface, such as home routers and IoT gateways.

Remediation

Upgrade RaspAP raspap-webgui to version 3.5.6 or later where the input is sanitized. If upgrade is not possible, disable remote access to the web interface or restrict it to trusted IPs. Additionally, apply a firewall rule to block outbound connections to the wpa_supplicant command or use SELinux/AppArmor to confine the web server process.

Risk context

Severity is medium (CVSS 4.7/5.1). No EPSS data available. The vulnerability is publicly known and exploitable remotely, so defenders should prioritize remediation.

Affected products

  • RaspAP raspap-webgui 3.5.5 and earlier

Scores

Severity
medium
CVSS v2
5.8
CVSS v3
4.7
CVSS v4
5.1
EPSS
—

os-command-injection raspap remote-exploit web-interface medium-severity command-injection networking

← All CVEs