PT-2020-15746 · Raspap · Raspap

Lb0X

·

Published

2020-08-24

·

Updated

2020-09-01

·

CVE-2020-24572

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RaspAP version 2.5
Description An issue in the includes/webconsole.php file allows an attacker with authenticated access to exploit a misconfigured web console. This can lead to attacks on the underlying OS, which is typically a Raspberry Pi system running this software. The exploitation can result in the execution of system commands, including those for uploading files and executing code.
Recommendations For RaspAP version 2.5, consider restricting access to the web console and limiting the execution of system commands to mitigate the risk of exploitation. As a temporary workaround, restrict the use of the web console until a patch or configuration fix is available.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24572

Affected Products

Raspap