RaspAP raspap-webgui OpenVPN Configuration del_ovpncfg.php escapeshellcmd os command injection
30Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3
exploitation probability
—
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escapeshellcmd of the file ajax/openvpn/del_ovpncfg.php of the component OpenVPN Configuration Handler. Such manipulation of the argument cfg_id leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
RaspAP · raspap-webguipublic PoCs found — 1
cve_referencegist.github.com/simyat/10422042d6d5225b2beb87754de4b68cunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.