CVE-2021-38557: High severity RaspAP RaspAP vulnerability
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data account can also overwrite /etc/raspap/hostapd/enablelog.sh with any executable content.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Set ownership and permissions on /etc/raspap/hostapd/enablelog.sh so that www-data cannot overwrite it, preventing attacker-controlled executable content from being used when the script is run as root.
RaspAP hostapd enablelog script /etc/raspap/hostapd/enablelog.sh file permissions/ownership = Non-writable by www-data (ensure it cannot be overwritten by the web server user) - Compensating control
Restrict the ability for the web server user (www-data) to run privileged scripts: remove/adjust the sudoers entry that allows www-data to execute /etc/raspap/hostapd/enablelog.sh as root without a password, so that sudo no longer grants root execution to www-data.
Event History
Frequently Asked Questions
What is CVE-2021-38557?
CVE-2021-38557 is a vulnerability in RaspAP 2.6.6 that allows attackers to execute commands as root due to insecure sudoers permissions.
How severe is CVE-2021-38557?
CVE-2021-38557 has a severity score of 8.8 (critical).
What is the affected software version of CVE-2021-38557?
The affected software version of CVE-2021-38557 is RaspAP 2.6.6.
How can an attacker exploit CVE-2021-38557?
An attacker can exploit CVE-2021-38557 by using the insecure sudoers permissions in RaspAP 2.6.6 to execute commands as root.
Is there a fix available for CVE-2021-38557?
Yes, a fix for CVE-2021-38557 is available. It is recommended to update to a patched version of RaspAP.