{"ok":true,"trend":{"id":385039,"platform":"mastodon","region":"global","key":"🚨 raspap mass disclosure — 3 cves, no patch cve-2026-101860 (cvss 8.8) — privilege escalation via sudoers manipulation →","title":"🚨 RaspAP Mass Disclosure — 3 CVEs, no patch CVE-2026-101860 (CVSS 8.8) — privilege escalation via sudoers manipulation →","url":"https://infosec.exchange/@threataft/117355427526065887","first_seen":"2026-09-29T17:43:50.364482Z","last_seen":"2026-09-29T17:43:50.364482Z","last_rank":7,"peak_rank":2,"last_volume":2,"peak_volume":2,"seen_count":1,"score":59.98,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"Security researchers have disclosed three vulnerabilities in RaspAP, the popular router software for Raspberry Pi, with no patches available. The most severe, CVE-2026-101860 with a CVSS score of 8.8, allows privilege escalation to root via sudoers manipulation. Two further flaws, CVE-2026-101859 (5.4) and CVE-2026-101858 (4.7), involve OS command injection, including through the OpenVPN handler and WiFiManager SSID handling.","why":"Unpatched vulnerabilities with root access implications on widely used Raspberry Pi router software raise immediate concern for users of exposed devices","tone":"negative","entities":["RaspAP","Raspberry Pi","CVE-2026-101860"],"summarized_at":"2026-09-29T17:44:10.041614Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1301},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"RaspAP hit with three unpatched CVE disclosures","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-09-29T17:43:50.364482Z","rank":2,"volume":2},{"captured_at":"2026-09-29T17:43:50.364482Z","rank":7,"volume":2}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@threataft/117355427526065887","author":"threataft@infosec.exchange","title":null,"snippet":"🚨 RaspAP Mass Disclosure — 3 CVEs, no patch CVE-2026-101860 (CVSS 8.8) — privilege escalation via sudoers manipulation → root on the Pi CVE-2026-101859 (CVSS 5.4) — OS command injection, OpenVPN handler CVE-2026-101858 (CVSS 4.7) — OS command injection, WiFiManager SSID Public…","posted_at":"2026-09-29T17:08:33Z","likes":2}],"elsewhere":[],"window":"7d"}}