CVE-2022-39986
RaspAP 2.8.7 Unauthenticated Command Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.
Una vulnerabilidad de inyección de comandos en RaspAP afecta a las versiones desde la 2.8.0 a la 2.8.7, la cual permite a atacantes no autenticados ejecutar comandos arbitrarios a través del parámetro cfg_id en /ajax/openvpn/activate_ovpncfg.php y /ajax/openvpn/del_ovpncfg.php.
RaspAP is feature-rich wireless router software that just works on many popular Debian-based devices, including the Raspberry Pi. A Command Injection vulnerability in RaspAP versions 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands in the context of the user running RaspAP via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php. Successfully tested against RaspAP 2.8.0 and 2.8.7.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2022-09-06 CVE Reserved
- 2023-08-01 CVE Published
- 2023-08-15 First Exploit
- 2024-10-21 CVE Updated
- 2025-02-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
CAPEC
References (8)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/174190 | 2023-08-15 | |
https://github.com/tucommenceapousser/RaspAP-CVE-2022-39986-PoC | 2023-08-16 | |
https://github.com/mind2hex/CVE-2022-39986 | 2023-11-28 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/RaspAP/raspap-webgui/blob/master/ajax/openvpn/activate_ovpncfg.php | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Raspap Search vendor "Raspap" | Raspap Search vendor "Raspap" for product "Raspap" | >= 2.8.0 <= 2.8.7 Search vendor "Raspap" for product "Raspap" and version " >= 2.8.0 <= 2.8.7" | - |
Affected
|