CVE-2024-28754
PHP vulnerability analysis and mitigation

Overview

RaspAP (aka raspap-webgui) through version 3.0.9 contains multiple critical security vulnerabilities that allow remote attackers to cause persistent denial of service (bricking), read sensitive files, and potentially execute arbitrary code. The vulnerability was discovered and disclosed on March 8, 2024 (Carrot Disclosure).

Technical details

Multiple vulnerabilities were demonstrated including the ability to read sensitive system files like /etc/passwd, leak WiFi passwords, extract WireGuard keys, and cause permanent denial of service through system bricking. The vulnerabilities appear to stem from insufficient input validation and authentication controls in the web interface. The CVSS score assigned by CISA-ADP is 7.5 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) (NVD).

Impact

The vulnerabilities allow attackers to gain unauthorized access to sensitive system information including passwords and encryption keys, perform man-in-the-middle attacks, and permanently disable affected systems through bricking attacks. The combination of these vulnerabilities effectively compromises the confidentiality, integrity and availability of affected RaspAP installations (Carrot Disclosure).

Exploitability

The vulnerabilities are easily exploitable remotely with no authentication required in some cases. Working proof-of-concept exploit code has been demonstrated that can read system files, extract credentials, and brick systems in just minutes. The researcher indicated additional code execution vulnerabilities likely exist but weren't fully explored (Carrot Disclosure).

Mitigation and workarounds

Initial fixes have been implemented through pull requests that add improved input escaping and authentication requirements for AJAX requests. However, the original researcher indicates additional security hardening is still needed. Users should upgrade to fixed versions when available and consider disabling external access to the RaspAP interface (Carrot Disclosure).

Community reactions

The disclosure prompted rapid response from the RaspAP maintainers, with multiple pull requests being submitted to address the vulnerabilities. The 'Carrot Disclosure' approach used by the researcher successfully motivated quick security improvements while withholding full exploit details (Carrot Disclosure).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-59989CRITICAL9.2
  • PHP logoPHP
  • phalcon/cphalcon
NoYesAug 21, 2026
CVE-2026-63135HIGH8.2
  • PHP logoPHP
  • yourls/yourls
NoYesAug 21, 2026
GHSA-p2ch-c2c3-4xm5MEDIUM6.1
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026
GHSA-8hgv-xc77-jmcrMEDIUM5.1
  • PHP logoPHP
  • getgrav/grav
NoYesAug 21, 2026
GHSA-hq84-x37p-j6q5MEDIUM4.5
  • PHP logoPHP
  • winter/wn-backend-module
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management