Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component that can result in remote command execution with root privileges.
References
Link | Resource |
---|---|
https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L510 | Exploit Third Party Advisory |
https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L216 | Exploit Third Party Advisory |
https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L314 | Exploit Third Party Advisory |
https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L407 | Exploit Third Party Advisory |
https://gist.github.com/omriinbar/52c000c02a6992c6ce68d531195f69cf | Third Party Advisory |
https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L231 | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-06-09 11:15
Updated : 2021-06-21 09:11
NVD link : CVE-2021-33356
Mitre link : CVE-2021-33356
JSON object : View
CWE
CWE-269
Improper Privilege Management
Products Affected
raspap
- raspap