CVE-2022-31126: Unauthenticated Remote Code Execution in Roxy-wi
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31126?
CVE-2022-31126 has been classified as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2022-31126?
To mitigate CVE-2022-31126, it is recommended to upgrade Roxy-wi to version 6.1.1.0 or later.
Who is affected by CVE-2022-31126?
CVE-2022-31126 affects all Roxy-wi versions prior to 6.1.1.0.
What type of attack does CVE-2022-31126 enable?
CVE-2022-31126 allows attackers to execute arbitrary code remotely by sending a specially crafted HTTP request.
What component of Roxy-wi is vulnerable in CVE-2022-31126?
The vulnerability in CVE-2022-31126 exists within the /app/options.py file of Roxy-wi.