PT-2025-27229 · Raspap · Raspap

Published

2025-06-27

·

Updated

2025-06-27

·

CVE-2025-44163

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions: RaspAP raspap-webgui version 3.3.1
Description: The issue allows an authenticated attacker to perform a Directory Traversal attack. This is achieved by sending a crafted POST request to the "ajax/networking/get wgkey.php" endpoint with a path traversal payload in the entity parameter. The vulnerability exploits the tee command used in shell execution, enabling the attacker to overwrite arbitrary files that are writable by the web server.
Recommendations: For RaspAP raspap-webgui version 3.3.1, consider restricting access to the "ajax/networking/get wgkey.php" endpoint until a patch is available. As a temporary workaround, avoid using the entity parameter in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2025-44163
GHSA-277F-37GW-9GMQ

Affected Products

Raspap