Record summary

CVE-2022-31125 has a selected CVSS score of 10.0 (critical); EIP currently links 1 catalogued exploit.

Description

Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request. This affects Roxywi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List< 6.1.1.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBRoxy WI v6.1.0.0 - Improper Authentication ControlExploitDB exploitby Nuri ÇilengirNot analyzed1 file
ExploitDB

PoC details

References

2