Products: 2
    Vulnerabilities: 16
    Known Exploited: 0
    4
    Critical Level Threats
    9
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-24788

    RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product.

    Last Modified: Jun 18, 2026
    Published: Feb 02, 2026

    CVE-2025-50428

    In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.

    Last Modified: Sep 09, 2025
    Published: Aug 27, 2025

    CVE-2025-44163

    RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable by the web server via abuse of the `tee` command used in shell execution.

    Last Modified: Nov 10, 2025
    Published: Jun 27, 2025

    CVE-2024-36622

    In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.

    Last Modified: Jul 02, 2025
    Published: Nov 29, 2024

    CVE-2024-2497

    RaspAP raspap-webgui HTTP POST Request provider.php code injection

    Last Modified: Apr 09, 2025
    Published: Mar 15, 2024
    Items Per Page
    Raspap Vulnerabilities & Security CVEs | CVE-DB