CVE-2025-50428

In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.
Configurations

No configuration.

History

29 Aug 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-77
References () https://blog.smarttecs.com/posts/2025-004-cve-2025-50428/ - () https://blog.smarttecs.com/posts/2025-004-cve-2025-50428/ -

29 Aug 2025, 16:24

Type Values Removed Values Added
Summary
  • (es) En RaspAP raspap-webgui 3.3.2 y versiones anteriores, existe una vulnerabilidad de inyección de comandos en el script "includes/hostapd.php". Esta vulnerabilidad se debe a una depuración incorrecta de la entrada del usuario enviada a través del parámetro de interfaz.

27 Aug 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-27 17:15

Updated : 2025-08-29 19:15


NVD link : CVE-2025-50428

Mitre link : CVE-2025-50428

CVE.ORG link : CVE-2025-50428


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')