Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Version 6.1.1.0 contains a patch for this issue.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:LRoxy Wi
APPRoxy-Wi< 6.1.1.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2022-31137CRITICAL10.0PL ✓same product
RCE w Roxy-WI — command injection bez uwierzytelnienia (CVSS 10.0)
CVE-2022-31126CRITICAL10.0PL ✓same product
Roxy-Wi: zdalne wykonanie kodu bez uwierzytelnienia (RCE)
CVE-2022-31125CRITICAL10.0PL ✓same product
Roxy-Wi: Ominięcie uwierzytelnienia (Auth Bypass) przez spreparowane żądanie HTTP
CVE-2021-38167CRITICAL9.8PL ✓same product
SQL Injection w Roxy-WI umożliwiający ominięcie uwierzytelnienia
CVE-2026-33076HIGH8.9same product
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6....