Sceawere
Vulnerability Detail
CVE-2026-101859UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
RaspAP OS Command Injection
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 5h ago
- Vendor
- RaspAP
- Product
- raspap-webgui
- Attack Type
- OS Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escapeshellcmd of the file ajax/openvpn/del_ovpncfg.php of the component OpenVPN Configuration Handler. Such manipulation of the argument cfg_id leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-09-29T02:16:54.607Z",
"pubdate": "2026-09-29T02:16:54.607Z",
"executiveSummary": "A critical OS command injection vulnerability exists in the OpenVPN Configuration Handler component of RaspAP raspap-webgui versions up to 3.5.5.\nThe vulnerability originates from the improper neutralization of user-supplied input passed to the escapeshellcmd function within the ajax/openvpn/del_ovpncfg.php file.\nAn unauthenticated or remote attacker can leverage this flaw to inject arbitrary shell commands, which are subsequently executed by the underlying operating system with the privileges of the web server process.\nSuccessful exploitation poses a severe security risk, potentially leading to full system compromise, unauthorized data access, and persistent control over the host device.\nGiven the public availability of exploit material and the lack of vendor response, the risk of active exploitation is significant for exposed RaspAP instances.",
"technicalDetails": "The vulnerability resides in the file ajax/openvpn/del_ovpncfg.php, which is part of the RaspAP OpenVPN Configuration Handler. The application processes the 'cfg_id' parameter to perform administrative actions on OpenVPN configuration files stored on the filesystem.\nThe root cause is the insecure handling of the 'cfg_id' variable before it is passed to system shell execution functions. While the code attempts to utilize the escapeshellcmd function, this function is insufficient for sanitizing arguments that are expected to be treated as discrete parameters in a shell command. escapeshellcmd escapes characters like #, &, ;, `, |, *, ?, ~, <, >, ^, (, ), [, ], {, }, $, and newline, but it does not prevent command chaining or argument injection if the input is improperly positioned within the command string.\nAn attacker can manipulate the 'cfg_id' parameter to break out of the intended command context. By injecting shell metacharacters such as backticks (``), subshells ($()), or logical operators (&&, ||), an attacker can append malicious commands to the execution flow. Because the application logic executes these commands with the privilege level of the web user (typically 'www-data' or 'root' in many Raspberry Pi RaspAP deployments), the malicious payload inherits those permissions.\nThe attack flow proceeds as follows: First, the attacker identifies a target RaspAP instance reachable over the network. Second, the attacker crafts a malicious HTTP request targeting ajax/openvpn/del_ovpncfg.php, setting the 'cfg_id' parameter to a string containing command separators followed by arbitrary shell commands (e.g., '123; id; cat /etc/shadow'). Third, the web server processes the script, passes the tainted input to the system shell execution path, and triggers the unintended commands. Fourth, the shell executes the injected payload and returns the output—or executes the side effects—directly on the host OS.\nThis vulnerability is particularly dangerous because it allows for remote code execution (RCE) without requiring prior authentication. Post-exploitation impact includes the installation of backdoors, deployment of further malicious software, pivoting into the local network where the RaspAP device resides, and complete unauthorized data exfiltration."
}