CVE-2021-33357: OS Command Injection
A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/getnetcfg.php, when the "iface" parameter value contains special characters such as ";" which enables an unauthenticated attacker to execute arbitrary OS commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-33357?
The severity of CVE-2021-33357 is critical with a CVSS score of 9.8.
How does CVE-2021-33357 affect RaspAP?
CVE-2021-33357 affects RaspAP versions 2.6 to 2.6.5.
What is the vulnerability in RaspAP?
The vulnerability in RaspAP is in the "iface" GET parameter in /ajax/networking/get_netcfg.php.
How can an attacker exploit CVE-2021-33357?
An unauthenticated attacker can exploit CVE-2021-33357 by using special characters in the "iface" parameter value to execute arbitrary OS commands.
Are there any available fixes for CVE-2021-33357?
No available fixes have been mentioned at this time. It is recommended to update to a version above 2.6.5 or apply any available patches.