在 RaspAP 的 raspap-webgui(最高至 3.5.5 版本)中发现了一个漏洞。该问题影响组件“sudo 配置”中的文件 src/RaspAP/Plugins/PluginInstaller.php 中的 PluginInstaller::addSudoers 函数。执行特定操作会导致权限管理不当。该漏洞可从远程发起攻击,相关利用代码已公开,并可被实际使用。尽管供应商在披露此事前已被联系,但未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| RaspAP | raspap-webgui | 3.5.0 |
cpe:2.3:a:raspap:raspap-webgui:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101859 | 5.4 MEDIUM | RaspAP raspap-webgui OpenVPN Configuration del_ovpncfg.php escapeshellcmd os command injec |
| CVE-2026-101858 | 4.7 MEDIUM | RaspAP raspap-webgui SSID Processing WiFiManager.php writeWpaSupplicant os command injecti |
No comments yet