u/InterestingFriend748

Hello everyone, I was solving a question in a "Wi-Fi Penetration Testing Tools and Techniques" module and I get stuck in checking router for firmware vulns section where it asked me to exploit a vulnerability for a RaspAP v2.6.6 command injection lead to RCE. As an exploit script exists in attacker machine but it fails multiple time when running it. Also burpsuite was installed but the proxy and chrominum wasn't installed to be able to intercept the request and modify the payload. So I decided to re-write the exploit again and find what is missing that cause failed to execute.

So I've fixed the exploit and uploaded it in my github account to anyone stuck in this section too! And off course helping the hackthebox community and share knowledge ;)

https://github.com/saherm0hamed/CVE-RaspAP-2.6.6-RCE

u/InterestingFriend748 — 21 days ago