Command Injection Vulnerability in RaspAP Web GUI by RaspAP
CVE-2025-50428
9.8CRITICAL
What is CVE-2025-50428?
The RaspAP Web GUI, specifically versions 3.3.2 and earlier, contains a command injection vulnerability within the includes/hostapd.php script. This vulnerability arises from improper sanitization of user input through the interface parameter, which can allow an attacker to execute arbitrary commands on the server. It is crucial for users to apply the necessary patches and update their systems to mitigate the risks associated with this vulnerability.
