An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the management script x-ui passes the no check certificate option to wget when downloading updates
The x-ui management script calls the wget tool with an option that disables TLS certificate verification (--no-check-certificate) during update download. This means the HTTPS connection is not properly validated, and an attacker on the network path can substitute a malicious payload for the legitimate update. The downloaded and executed file can contain arbitrary code that will run in the context of the management script's privileges.
An attacker can execute arbitrary code on the victim's server, which in practice means complete takeover of the system, including access to configuration data, keys, and network traffic handled by 3X-Ui.
Update 3X-Ui to version 2.5.3 or newer. Patch details are available in the vendor references (pull request #2661 on GitHub).
MHSanaei 3X-Ui in versions before v2.5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMhsanaei 3x Ui
APPMhsanaei< 2.5.3