medium · CVSS v3 5.4 · CVSS v4 5.3
CVE-2026-101859
A command‑injection flaw exists in RaspAP raspap‑webgui’s OpenVPN configuration handler, allowing remote attackers to execute arbitrary OS c
Overview
A command‑injection flaw exists in RaspAP raspap‑webgui’s OpenVPN configuration handler, allowing remote attackers to execute arbitrary OS commands via the cfg_id parameter. This can compromise the confidentiality, integrity, and availability of the device and any connected networks.
Description
A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escapeshellcmd of the file ajax/openvpn/del_ovpncfg.php of the component OpenVPN Configuration Handler. Such manipulation of the argument cfg_id leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
The vulnerability permits remote code execution, enabling attackers to read, modify, or delete files, install malware, or take full control of the device. This threatens the confidentiality, integrity, and availability of the system and any networks it connects to. Defenders should treat compromised devices as potentially fully controlled by an attacker.
Remediation
Upgrade RaspAP raspap‑webgui to version 3.5.6 or later, where the OpenVPN delete handler sanitizes input. If an upgrade is not immediately possible, block or restrict access to the /ajax/openvpn/del_ovpncfg.php endpoint, or enforce strict input validation on cfg_id. Monitor logs for anomalous shell command usage.
Risk context
Severity is medium (CVSS 5.4) and no EPSS data is available. The flaw is publicly disclosed and exploitable remotely, so defenders should act promptly but the risk is moderate.
Affected products
- RaspAP raspap-webgui 3.5.5 and earlier
Scores
- Severity
- medium
- CVSS v2
- 5.5
- CVSS v3
- 5.4
- CVSS v4
- 5.3
- EPSS
- —