漏洞描述
RaspAP 2.6 to 2.6.5 allows unauthenticated attackers to execute arbitrary OS commands via the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as ";".
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
checkmarx.comhttps://checkmarx.com/blog/chained-raspap-vulnerabilities-grant-root-level-access/↗gist.github.comhttps://gist.github.com/omriinbar/52c000c02a6992c6ce68d531195f69cf↗github.comhttps://github.com/RaspAP/raspap-webgui↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-33357↗github.comhttps://github.com/20142995/Goby↗