CVE-2022-39986: Command Injection
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfgid parameter in /ajax/openvpn/activateovpncfg.php and /ajax/openvpn/delovpncfg.php.
Other sources
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfgid parameter in /ajax/openvpn/activateovpncfg.php and /ajax/openvpn/delovpncfg.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39986?
The severity of CVE-2022-39986 is critical, with a CVSS score of 9.8.
How does the Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 occur?
The Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 occurs when unauthenticated attackers are able to execute arbitrary commands via the `cfg_id` parameter in `/ajax/openvpn/activate_ovpncfg.php` and `/ajax/openvpn/del_ovpncfg.php`.
Who is affected by the Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7?
Any users of RaspAP versions 2.8.0 through 2.8.7 are affected by the Command injection vulnerability.
How can I fix the Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7?
To fix the Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7, it is recommended to update to a version later than 2.8.7, if available.
Where can I find more information about CVE-2022-39986?
You can find more information about CVE-2022-39986 on the NIST National Vulnerability Database (NVD) website.