CVE-2022-39987: Command Injection
A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the "entity" POST parameters in /ajax/networking/getwgkey.php.
Other sources
A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the entity POST parameters in /ajax/networking/getwgkey.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39987?
The severity of CVE-2022-39987 is high with a CVSS score of 8.8.
How does the Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 work?
The vulnerability allows an authenticated attacker to execute arbitrary OS commands as root by exploiting the `entity` POST parameters in `/ajax/networking/get_wgkey.php`.
Which software versions are affected by CVE-2022-39987?
RaspAP versions 2.8.0 through 2.9.2 and the composer/billz/raspap-webgui package between versions 2.8.0 and 2.9.2 are affected.
Is authentication required to exploit the vulnerability in RaspAP 2.8.0 thru 2.9.2?
Yes, the attacker needs to be authenticated in order to exploit the vulnerability.
How can I fix the Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2?
Upgrade RaspAP or composer/billz/raspap-webgui package to a version beyond 2.9.2.