CVE-2022-31137
CRITICAL EXPLOITED IN THE WILD NUCLEIRoxy-WI < 6.1.1.0 - Unauthenticated Remote Code Execution via subprocess_execute Function
Title source: llmExploitation Summary
CVE-2022-31137 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).
EIP tracks 1 public exploit, including a Metasploit module exploits/linux/http/roxy_wi_exec.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated command injection vulnerability in Roxy-WI prior to version 6.1.1.0, allowing remote code execution under the context of the web server user. The exploit leverages a POST request to inject commands via the 'ipbackend' parameter.
Description
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Exploits (1)
This Metasploit module exploits an unauthenticated command injection vulnerability in Roxy-WI prior to version 6.1.1.0, allowing remote code execution under the context of the web server user. The exploit leverages a POST request to inject commands via the 'ipbackend' parameter.
Nuclei Templates (1)
http.html:"Roxy-WI" || http.html:"roxy-wi"
body="roxy-wi"
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H