CVE-2021-38556: Command Injection
includes/configureclient.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
RaspAP 2.6.6 (includes/configure_client.php)to a version that resolves this vulnerability.Fixed in 2.6.6
Event History
Frequently Asked Questions
What is CVE-2021-38556?
CVE-2021-38556 is a vulnerability in RaspAP 2.6.6 that allows attackers to execute commands via command injection.
What is the severity of CVE-2021-38556?
The severity of CVE-2021-38556 is high with a CVSS score of 8.8.
How does CVE-2021-38556 affect RaspAP?
CVE-2021-38556 affects RaspAP version 2.6.6, allowing attackers to execute commands via command injection.
How can I fix CVE-2021-38556?
To fix CVE-2021-38556, update RaspAP to a version that is not affected by this vulnerability.
Where can I find more information about CVE-2021-38556?
You can find more information about CVE-2021-38556 on the RaspAP GitHub repository and Zero Security Penetration Testing website.