跳转到帖子

RaspAP Unauthenticated Command Injection

recommended_posts

发布于
  • Members

RaspAP Unauthenticated Command Injection

Disclosed
07/31/2023
Created
08/15/2023

Description

RaspAP is feature-rich wireless router software that just works on many popular Debian-based devices, including the Raspberry Pi. A Command Injection vulnerability in RaspAP versions 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands in the context of the user running RaspAP via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php. Successfully tested against RaspAP 2.8.0 and 2.8.7.

Author(s)

Platform

Linux,Unix

Architectures

cmd, x86, x64

Development

  • Source Code
  • History
  • 查看数 701
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…