A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfgid parameter in /ajax/openvpn/activateovpncfg.php and /ajax/openvpn/del_ovpncfg.php.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39986.json"