vendor:
Roxy WI
by:
Iyaad Luqman K
9.8
CVSS
CRITICAL
Unauthenticated Remote Code Execution (RCE)
78
CWE
Product Name: Roxy WI
Affected Version From: Roxy WI <= v6.1.0.0
Affected Version To: Roxy WI <= v6.1.0.0
Patch Exists: NO
Related CWE: CVE-2022-31137
CPE: a:roxy_wi:roxy_wi:6.1.0.0
Platforms Tested: Ubuntu 22.04
2022
Roxy WI v6.1.0.0 – Unauthenticated Remote Code Execution (RCE) via subprocess_execute
The vulnerability allows unauthenticated remote attackers to execute arbitrary code on the target system via the subprocess_execute function in the Roxy WI application. By sending a specially crafted request to the options.py endpoint, an attacker can inject malicious commands that will be executed with the privileges of the application.
Mitigation:
Apply the vendor-provided patch or upgrade to a version that includes a fix for the vulnerability. Additionally, restrict access to the application to trusted users and networks.