CVE-2021-33356: Critical severity raspap vulnerability
Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component that can result in remote command execution with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33356?
CVE-2021-33356 refers to multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 that could allow an authenticated remote attacker to inject arbitrary commands to a component and execute remote commands with root privileges.
What is the severity of CVE-2021-33356?
The severity of CVE-2021-33356 is critical with a CVSS score of 8.8.
How can an attacker exploit CVE-2021-33356?
An attacker can exploit CVE-2021-33356 by injecting arbitrary commands to the /installers/common.sh component.
What is the affected software for CVE-2021-33356?
The affected software for CVE-2021-33356 is RaspAP versions 1.5 to 2.6.5.
Is there a fix available for CVE-2021-33356?
Yes, you can find the fix for CVE-2021-33356 on the GitHub repository of RaspAP.