Multiple privilege escalation vulnerabilities in RaspAP 1.5 to 2.6.5 could allow an authenticated remote attacker to inject arbitrary commands to /installers/common.sh component that can result in remote command execution with root privileges.
| Software | From | Fixed in |
|---|---|---|
| raspap / raspap | 1.5 | 2.6.5.x |