CVE-2021-38557
24.08.2021, 13:15
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions. The www-data account can execute /etc/raspap/hostapd/enablelog.sh as root with no password; however, the www-data account can also overwrite /etc/raspap/hostapd/enablelog.sh with any executable content.Enginsight
Vendor | Product | Version |
---|---|---|
raspap | raspap | 2.6.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References