CVE-2026-101858
Received Received - Intake

Command Injection in RaspAP WebGUI

Vulnerability report for CVE-2026-101858, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulDB

Description

A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of the file src/RaspAP/Networking/Hotspot/WiFiManager.php of the component SSID Processing. This manipulation of the argument ssid causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
raspap raspap-webgui to 3.5.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an OS command injection flaw in RaspAP raspap-webgui versions up to 3.5.5. It exists in the WiFiManager::writeWpaSupplicant function in src/RaspAP/Networking/Hotspot/WiFiManager.php. The issue allows an attacker to inject commands via the SSID parameter during network configuration, leading to remote code execution.

Detection Guidance

Check RaspAP WebGUI logs for unusual SSID inputs or command execution attempts. Monitor network traffic for unexpected outbound connections from the RaspAP host. Review files modified by the www-data user, especially in /etc/raspap/ or related directories.

Impact Analysis

An attacker could remotely execute arbitrary commands on the affected system with the privileges of the www-data user. This could allow them to delete files, modify configurations, or escalate privileges to root. The exploit can be performed without authentication and has been publicly documented.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating confidentiality requirements in GDPR and HIPAA. Remote code execution may allow attackers to exfiltrate sensitive data, tamper with records, or disrupt operations, resulting in non-compliance and potential legal penalties.

Mitigation Strategies

Upgrade RaspAP WebGUI to the latest version if available. Restrict network access to RaspAP management interface. Disable or remove the vulnerable SSID processing function if no patch exists. Monitor for signs of exploitation like unexpected processes or file changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101858. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart