CVE-2024-41637: Raspap
High severity, CVSS 8.3. EPSS: 0.8% chance of exploitation in the next 30 days.
RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo privileges to execute several critical commands without a password.
Affected products
- Raspap Raspap: before 3.1.5 (fixed in 3.1.5)
Published 2024-07-29. Last modified 2026-06-17.