{ "id": "CVE-2022-39987", "sourceIdentifier": "cve@mitre.org", "published": "2023-08-01T14:15:09.937", "lastModified": "2023-08-01T15:25:40.337", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the \"entity\" POST parameters in /ajax/networking/get_wgkey.php." } ], "metrics": {}, "references": [ { "url": "https://github.com/RaspAP/raspap-webgui/blob/master/ajax/networking/get_wgkey.php", "source": "cve@mitre.org" }, { "url": "https://medium.com/@ismael0x00/multiple-vulnerabilities-in-raspap-3c35e78809f2", "source": "cve@mitre.org" } ] }