RaspAP vendor intelligence
RaspAP Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting RaspAP products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 2
- Known exploited vulnerabilities affecting RaspAP products
- In CISA KEV
- 0
- Records also listed in the official catalog
- Beyond CISA KEV
- 2
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- RaspAP KEVs with sensor-observed exploitation activity
Review RaspAP exploitation against the products you run
Review exploited RaspAP vulnerabilities against the products you run. CISA KEV coverage is shown below.
- 0%
- Covered by CISA
- 100%
- Beyond CISA
- 1
- Product families
Attested RaspAP vulnerabilities
2 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-39986
A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id... |
RaspAP | High | Beyond CISA | 19 Sep 2025 |
|
CVE-2021-33357
A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value... |
RaspAP | High | Beyond CISA | 09 Jun 2021 |
No RaspAP vulnerabilities match this search or filter.
Showing 2 of 2 RaspAP known exploited vulnerabilities.
Recurring weakness patterns
Neutralization and neutralization account for two mapped occurrences across this RaspAP KEV portfolio.