<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>RaspAP - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/raspap/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 02:24:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/raspap/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Management Vulnerability in RaspAP raspap-webgui</title><link>https://feed.craftedsignal.io/briefs/2026-09-raspap-privilege-escalation/</link><pubDate>Tue, 29 Sep 2026 02:24:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-raspap-privilege-escalation/</guid><description>An improper privilege management vulnerability in RaspAP raspap-webgui allows remote attackers to manipulate sudo configuration files, potentially leading to unauthorized privilege escalation.</description><content:encoded><![CDATA[<p>A security vulnerability exists in RaspAP raspap-webgui versions 3.5.5 and earlier. The flaw resides within the PluginInstaller::addSudoers function located in 'src/RaspAP/Plugins/PluginInstaller.php'. The component responsible for sudo configuration management fails to properly sanitize or restrict inputs, allowing an attacker to perform unauthorized manipulations of the sudoers file. This vulnerability is classified as improper privilege management and can be initiated remotely. Publicly available exploit code exists, increasing the risk for internet-exposed instances of the web interface. Because the vendor has not responded to disclosure attempts, no official patch is available to remediate the vulnerability at this time. Defenders should isolate affected web interfaces or implement strict access controls to prevent unauthorized remote exploitation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an unauthenticated remote attacker to gain elevated privileges on the underlying host system. By manipulating the sudoers file, an attacker can grant themselves or other users unrestricted root execution permissions. This impact is significant given that RaspAP is typically used to manage networking hardware, and compromise would provide full control over the router or gateway functionality.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Restrict network access to the raspap-webgui interface to trusted management subnets using network-level firewalls.</li>
<li>Monitor the integrity of the /etc/sudoers file for unauthorized modifications.</li>
<li>Audit the raspap-webgui process for unexpected child processes or unusual shell spawns.</li>
<li>Disable the web-based sudo configuration component if it is not strictly required for environment operations.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>privilege-escalation</category></item></channel></rss>