CVE-2025-50428: Command Injection
Published Aug 27, 2025
·Updated
In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.
Affected Software
2 affected components
RaspAP raspap-webgui<=3.3.2
RaspAP raspap-webgui<=3.3.2
Remediation
Patch Available
Event History
Aug 27, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-50428?
CVE-2025-50428 is classified as a high-severity command injection vulnerability.
2
How do I fix CVE-2025-50428?
To fix CVE-2025-50428, upgrade RaspAP raspap-webgui to version 3.3.3 or later.
3
What products are affected by CVE-2025-50428?
CVE-2025-50428 affects RaspAP raspap-webgui version 3.3.2 and earlier.
4
What causes CVE-2025-50428 vulnerability?
CVE-2025-50428 is caused by improper sanitization of user inputs in the includes/hostapd.php script.
5
What type of vulnerability is CVE-2025-50428?
CVE-2025-50428 is a command injection vulnerability that allows attackers to execute arbitrary commands.