Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data account can also overwrite /etc/raspap/hostapd/enablelog.sh with any executable content.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
RaspAP安全漏洞
Vulnerability Description
RaspAP是应用软件基于 Debian 的设备的简单无线 AP 设置和管理 RaspAP 中存在安全漏洞。该漏洞允许攻击者以root用户执行命令,因为sudoers权限不安全。
CVSS Information
N/A
Vulnerability Type
N/A