CVE-2025-44163: Path Traversal
RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/getwgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the entity parameter to overwrite arbitrary files writable by the web server via abuse of the tee command used in shell execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44163?
CVE-2025-44163 is a high severity vulnerability due to its potential for arbitrary file overwriting via directory traversal.
How do I fix CVE-2025-44163?
To fix CVE-2025-44163, upgrade to RaspAP raspap-webgui version 3.3.6 or later.
Who is affected by CVE-2025-44163?
CVE-2025-44163 affects users of RaspAP raspap-webgui version 3.3.1 and earlier.
What type of attack does CVE-2025-44163 exploit?
CVE-2025-44163 exploits directory traversal to allow authenticated attackers to overwrite files.
What is the impact of CVE-2025-44163?
The impact of CVE-2025-44163 includes potential unauthorized file access and server compromise.