CVSS v3
8.8
HIGH
EPSS Score
42.1%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unrestricted) web console to attack the underlying OS (Raspberry Pi) running this software, and execute commands on the system (including ones for uploading of files and execution of code).
An issue was discovered in includes/webconsole.php in RaspAP 2.5. With authenticated access, an attacker can use a misconfigured (and virtually unrestricted) web console to attack the underlying OS (Raspberry Pi) running this software, and execute commands on the system (including ones for uploading of files and execution of code).
Active exploitation of CVE-2020-24572 has not been confirmed. The EPSS score is 42.1%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2020-24572 has a CVSS v3 base score of 8.8 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).