CVE-2022-31126
CRITICAL EXPLOITED NUCLEIRoxy-wi < 6.1.1.0 - Unauthenticated Remote Code Execution via /app/options.py
Title source: llmExploitation Summary
CVE-2022-31126 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Nuri Çilengir. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated remote code execution (RCE) vulnerability in Roxy WI v6.1.0.0 by sending a crafted POST request to /app/options.py with a command injection payload in the 'getcert' parameter. The payload executes the 'id' command, confirming arbitrary command execution.
Description
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.
Exploits (1)
This exploit demonstrates an unauthenticated remote code execution (RCE) vulnerability in Roxy WI v6.1.0.0 by sending a crafted POST request to /app/options.py with a command injection payload in the 'getcert' parameter. The payload executes the 'id' command, confirming arbitrary command execution.
Nuclei Templates (1)
html:"Roxy-WI"
body="roxy-wi"
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L