RaspAP Raspap-Webgui OS Command Injection Vulnerability

Vulnerability

An OS command injection vulnerability has been identified in RaspAP Raspap-Webgui versions prior to 3.3.6. This vulnerability allows a logged-in user to execute arbitrary OS commands on the server.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of OS commands, potentially allowing for further system compromise.

Remediation

Users are advised to update RaspAP Raspap-Webgui to version 3.3.6 or later.

Added: Feb 2, 2026, 5:24 AM
Updated: Feb 2, 2026, 5:24 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
4.9
remediation
7.7
relevance
2.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.