CVE-2022-39987: Improper Neutralization of Special Elements used in a Command ('Command Injection')
(updated )
A Command injection vulnerability in RaspAP 2.8.0 thru 2.9.2 allows an authenticated attacker to execute arbitrary OS commands as root via the “entity” POST parameters in /ajax/networking/get_wgkey.php.
References
Detect and mitigate CVE-2022-39987 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →