NA

CVE-2022-39986

Published: 01/08/2023 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated malicious users to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

raspap raspap

Github Repositories

bash script for automated discovery and exploitation of machines with the CVE-2022-39986 vulnerability

RaspAP Hunter RaspAP Hunter is a Bash script designed to scan for RaspAP installations and test them for a specific vulnerability CVE-2022-39986 ____ ___ ____ / __ \ ____ _ _____ ____ / | / __ \ / /_/ // __ `// ___// __ \ / /| | / /_/ / / _, _// /_/ /(__ )/ /_/ // ___ | / ____/ /_/ |_| \__,_//____// ___//_/ |_|/_/ __ _