CVE-2021-33358: OS Command Injection
Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpapassphrase" POST parameters in /hostapd, when the parameter values contain special characters such as ";" or "$()" which enables an authenticated attacker to execute arbitrary OS commands.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-33358?
CVE-2021-33358 is a vulnerability that exists in RaspAP versions 2.3 to 2.6.5.
What is the severity of CVE-2021-33358?
The severity of CVE-2021-33358 is critical with a CVSS score of 8.8.
What are the affected software versions of CVE-2021-33358?
RaspAP versions 2.3 to 2.6.5 are affected by CVE-2021-33358.
How can an attacker exploit CVE-2021-33358?
An authenticated attacker can exploit CVE-2021-33358 by using special characters in the "interface", "ssid", and "wpa_passphrase" POST parameters to execute arbitrary OS commands.
How can I fix CVE-2021-33358?
To fix CVE-2021-33358, it is recommended to update RaspAP to a version higher than 2.6.5.