Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component that can result in remote command execution with root privileges.
References
Configurations
History
21 Nov 2024, 06:08
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/omriinbar/52c000c02a6992c6ce68d531195f69cf - Third Party Advisory | |
References | () https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L216 - Exploit, Third Party Advisory | |
References | () https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L231 - Exploit, Third Party Advisory | |
References | () https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L314 - Exploit, Third Party Advisory | |
References | () https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L407 - Exploit, Third Party Advisory | |
References | () https://github.com/RaspAP/raspap-webgui/blob/5a7b77459839c9420fac0d10ec28cee1af9bb782/installers/common.sh#L510 - Exploit, Third Party Advisory |
Information
Published : 2021-06-09 18:15
Updated : 2024-11-21 06:08
NVD link : CVE-2021-33356
Mitre link : CVE-2021-33356
CVE.ORG link : CVE-2021-33356
JSON object : View
Products Affected
raspap
- raspap
CWE
CWE-269
Improper Privilege Management