Sceawere

Vulnerability Detail

CVE-2026-101858UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

RaspAP OS Command Injection Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
5h ago
Vendor
RaspAP
Product
raspap-webgui
Attack Type
OS Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. This manipulation of the argument ssid causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-09-29T02:16:54.417Z",
  "pubdate": "2026-09-29T02:16:54.417Z",
  "executiveSummary": "A critical OS command injection vulnerability has been identified in RaspAP raspap-webgui versions up to 3.5.5, specifically within the SSID processing logic of the WiFi manager.\nThis vulnerability allows an unauthenticated or remote attacker to inject and execute arbitrary system commands on the host operating system with the privileges of the web server process.\nThe flaw resides in the handling of the ssid parameter within the WiFiManager::writeWpaSupplicant function. Improper sanitization or validation of user-supplied input allows for shell metacharacter manipulation, leading to remote code execution.\nGiven that the exploit is publicly available and the vendor has remained unresponsive, the risk to affected systems is considered high.\nSuccessful exploitation compromises the integrity, confidentiality, and availability of the underlying device, potentially granting full system access to an adversary.\nImmediate mitigation is required, as this vulnerability poses a severe threat to any deployment where the RaspAP interface is accessible, either locally or via a network.",
  "technicalDetails": "The vulnerability is classified as an OS command injection flaw located in the src/RaspAP/Networking/Hotspot/WiFiManager.php file. The root cause is the insecure handling of the ssid argument passed to the WiFiManager::writeWpaSupplicant function. The application fails to adequately sanitize or escape user-supplied strings before integrating them into system-level operations or configuration files that are subsequently processed by shell-executed commands.\nThe exploitation mechanism leverages the lack of input validation to inject malicious shell commands. By embedding shell metacharacters—such as semicolons, backticks, or pipes—within the ssid parameter, an attacker can terminate the intended command and append arbitrary instructions that the operating system will then execute.\nThe attack flow begins with the attacker crafting a malicious payload directed at the SSID configuration endpoint of the web interface. When the application processes the request, the underlying PHP code passes the tainted ssid variable directly to a system command execution context (e.g., exec(), shell_exec(), or passthru()). Because the input is not treated as a literal string, the shell interprets the injected metacharacters as command separators or delimiters.\nFor example, an input designed as 'MyWiFi; rm -rf /; #' would force the server to execute both the intended network configuration command and the destructive system deletion command. Since the application likely runs with root or high-privilege permissions to manage network interfaces, the injected code is executed with equivalent privileges.\nThis vulnerability is remotely exploitable without requiring authentication, depending on the network exposure of the RaspAP web interface. The impact is absolute, as it allows for arbitrary code execution, which can lead to complete system compromise, the installation of persistent backdoors, data exfiltration, or the inclusion of the device into a botnet. Because no vendor patch is available, the exposure remains constant for all installations up to version 3.5.5."
}
CVE-2026-101858: RaspAP OS Command Injection Vulnerability (MEDIUM Severity, CVSS: 4.7) | Sceawere