CVE-2026-101859 | RaspAP raspap-webgui up to 3.5.5 OpenVPN Configuration del_ovpncfg.php escapeshellcmd cfg_id os command injection
A vulnerability labeled as critical has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escapeshellcmd of the file ajax/openvpn/del_ovpncfg.php of the component OpenVPN Configuration Handler. Such manipulation of the argument cfg_id leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-101859. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More