CVE-2026-24788

Publication date

2026-02-02 04:37:03

Family

jpcert

State

PUBLISHED

Description

RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product.