
Cloud Vulnerability DB
A community-led vulnerabilities database
RaspAP (aka raspap-webgui) through version 3.0.9 contains multiple critical security vulnerabilities that allow remote attackers to cause persistent denial of service (bricking), read sensitive files, and potentially execute arbitrary code. The vulnerability was discovered and disclosed on March 8, 2024 (Carrot Disclosure).
Multiple vulnerabilities were demonstrated including the ability to read sensitive system files like /etc/passwd, leak WiFi passwords, extract WireGuard keys, and cause permanent denial of service through system bricking. The vulnerabilities appear to stem from insufficient input validation and authentication controls in the web interface. The CVSS score assigned by CISA-ADP is 7.5 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) (NVD).
The vulnerabilities allow attackers to gain unauthorized access to sensitive system information including passwords and encryption keys, perform man-in-the-middle attacks, and permanently disable affected systems through bricking attacks. The combination of these vulnerabilities effectively compromises the confidentiality, integrity and availability of affected RaspAP installations (Carrot Disclosure).
The vulnerabilities are easily exploitable remotely with no authentication required in some cases. Working proof-of-concept exploit code has been demonstrated that can read system files, extract credentials, and brick systems in just minutes. The researcher indicated additional code execution vulnerabilities likely exist but weren't fully explored (Carrot Disclosure).
Initial fixes have been implemented through pull requests that add improved input escaping and authentication requirements for AJAX requests. However, the original researcher indicates additional security hardening is still needed. Users should upgrade to fixed versions when available and consider disabling external access to the RaspAP interface (Carrot Disclosure).
The disclosure prompted rapid response from the RaspAP maintainers, with multiple pull requests being submitted to address the vulnerabilities. The 'Carrot Disclosure' approach used by the researcher successfully motivated quick security improvements while withholding full exploit details (Carrot Disclosure).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."