CVE-2023-30260: Command Injection
Published Jun 23, 2023
·Updated
Command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier allows remote attackers to run arbitrary commands via crafted POST request to hostapd settings form.
Affected Software
1 affected component
RaspAP RaspAP<=2.8.8
Remediation
Patch Available
Event History
Jun 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-30260?
The severity of CVE-2023-30260 is high with a CVSS score of 8.8.
2
How does the command injection vulnerability in RaspAP raspap-webgui 2.8.8 and earlier work?
The vulnerability allows remote attackers to run arbitrary commands by sending a crafted POST request to the hostapd settings form.
3
What software versions are affected by CVE-2023-30260?
RaspAP raspap-webgui versions up to and including 2.8.8 are affected by CVE-2023-30260.
4
Are there any patches or fixes available for RaspAP raspap-webgui to address CVE-2023-30260?
Yes, a fix has been implemented in the latest version of RaspAP raspap-webgui. It is recommended to upgrade to the latest version.
5
Where can I find more information about CVE-2023-30260?
You can find more information about CVE-2023-30260 at the following references: [link1], [link2]