RaspAP是应用软件基于 Debian 的设备的简单无线 AP 设置和管理 RaspAP存在操作系统命令注入漏洞,该漏洞源于在RaspAP 2.6版本到2.6.5版本中未正确过滤“iface”参数中的“;”等特殊字符。攻击者利用该漏洞就可以执行任意的操作系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | RaspAP 2.6 to 2.6.5 allows unauthenticated attackers to execute arbitrary OS commands via the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as ";". | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-33357.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-3196 | 8.8 HIGH | Hitachi ID Bravura Security Fabric 数据伪造问题漏洞 |
| CVE-2020-24473 | Intel Server Board 缓冲区错误漏洞 | |
| CVE-2021-0105 | Intel PROSet Wireless 权限许可和访问控制问题漏洞 | |
| CVE-2020-24511 | Intel Processors 信息泄露漏洞 | |
| CVE-2020-24486 | Intel Processors 输入验证错误漏洞 | |
| CVE-2020-12360 | Intel Processors 缓冲区错误漏洞 | |
| CVE-2021-0095 | Intel Processors 处理逻辑错误漏洞 | |
| CVE-2020-12358 | Intel INTEL-SA-00463 缓冲区错误漏洞 | |
| CVE-2020-24512 | Intel Processors 信息泄露漏洞 | |
| CVE-2021-0097 | Intel Server Board M10JNP2SB 路径遍历漏洞 | |
| CVE-2020-24474 | Intel Server Board 缓冲区错误漏洞 | |
| CVE-2021-0113 | Intel Server Board M10JNP2SB缓冲区错误漏洞 | |
| CVE-2020-24475 | Intel Server Board 安全漏洞 | |
| CVE-2021-0001 | Intel Integrated Performance Primitives 安全漏洞 | |
| CVE-2021-0051 | Intel Server Platform Services 输入验证错误漏洞 | |
| CVE-2021-0055 | Intel NUC Kit 权限许可和访问控制问题漏洞 | |
| CVE-2021-0112 | Intel Unite 代码问题漏洞 | |
| CVE-2021-0098 | Intel Unite 安全漏洞 | |
| CVE-2021-0108 | Intel Unite 代码问题漏洞 | |
| CVE-2021-0102 | Intel Unite 权限许可和访问控制问题漏洞 |
Showing top 20 of 94 CVEs. View all on vendor page → →
No comments yet