vendor:
Roxy WI
by:
Nuri Çilengir
9.8
CVSS
CRITICAL
Unauthenticated Remote Code Execution (RCE)
79
CWE
Product Name: Roxy WI
Affected Version From: Roxy WI <= v6.1.1.0
Affected Version To: Roxy WI v6.1.1.0
Patch Exists: YES
Related CWE: CVE-2022-31161
CPE: a:roxy-wi:roxy-wi:6.1.1.0
Platforms Tested: Ubuntu 22.04
2022
Roxy WI v6.1.1.0 – Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload
The Roxy WI v6.1.1.0 application is vulnerable to unauthenticated remote code execution (RCE) via ssl_cert upload. An attacker can exploit this vulnerability by uploading a malicious ssl_cert file, which can lead to remote code execution.
Mitigation:
Update to the latest version of Roxy WI (v6.1.1.1 or higher) which includes a patch for this vulnerability. Additionally, restrict access to the Roxy WI application and regularly monitor for any suspicious activity.