Published:2026/02/02  Last Updated:2026/02/02

JVN#27202136
OS command injection in raspap-webgui

Overview

RaspAP raspap-webgui contains an OS command injection vulnerability.

Products Affected

  • raspap-webgui versions prior to 3.3.6

Description

RaspAP raspap-webgui contains the following vulnerability.

  • OS command injection (CWE-78)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 8.8
    • CVE-2026-24788

Impact

An arbitrary OS command may be executed by a user who can log in to the application.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Link
RaspAP Releases of raspap-webgui

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Taihei Kusayanagi of NTT Security (Japan) KK reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-24788
JVN iPedia JVNDB-2026-000014