{"cve":"CVE-2022-31126","epss":{"score":0.52649},"mitre":{"cpes":[],"created":"2022-07-06T17:30:13+00:00","description":"Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":10,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"},"cvssV4_0":{}},"mitre_repo_path":"cves/2022/31xxx/CVE-2022-31126.json","references":["https://github.com/hap-wi/roxy-wi/security/advisories/GHSA-mh86-878h-43c9"],"title":"Unauthenticated Remote Code Execution in Roxy-wi","updated":"2025-04-23T18:04:37.698000+00:00","vendors":[],"weaknesses":["CWE-74"]},"nvd":{"cpes":["cpe:2.3:a:roxy-wi:roxy-wi:*:*:*:*:*:*:*:*"],"created":"2022-07-06T18:15:19.433000+00:00","description":"Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.","metrics":{"cvssV2_0":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"cvssV3_0":{},"cvssV3_1":{"score":10.0,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"},"cvssV4_0":{}},"nvd_repo_path":"2022/CVE-2022-31126.json","references":["https://github.com/hap-wi/roxy-wi/security/advisories/GHSA-mh86-878h-43c9"],"title":null,"updated":"2026-06-17T04:44:51.480000+00:00","vendors":["roxy-wi","roxy-wi$PRODUCT$roxy-wi"],"weaknesses":["CWE-74"]},"opencve":{"changes":[{"created":"2025-04-23T19:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"23a79b52-c11e-4a3f-98a0-d9a8d01a4d95"},{"created":"2025-07-14T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.90097},"old":{"score":0.90547}}}},"type":"metrics"}],"id":"a6661a9a-baf2-419e-a5d2-44089202ec1a"},{"created":"2025-07-15T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.89598},"old":{"score":0.90097}}}},"type":"metrics"}],"id":"794ddef1-e223-463f-8d08-1683a0424afa"}],"cpes":{"data":["cpe:2.3:a:roxy-wi:roxy-wi:*:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2022-07-06T17:30:13+00:00","provider":"mitre"},"description":{"data":"Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":7.5,"vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P"},"provider":"nvd"},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":10,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.52649},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["https://github.com/hap-wi/roxy-wi/security/advisories/GHSA-mh86-878h-43c9"],"providers":["mitre","nvd"]},"title":{"data":"Unauthenticated Remote Code Execution in Roxy-wi","provider":"mitre"},"updated":{"data":"2025-04-23T18:04:37.698000+00:00","provider":"mitre"},"vendors":{"data":["roxy-wi","roxy-wi$PRODUCT$roxy-wi"],"providers":["nvd"]},"weaknesses":{"data":["CWE-74"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2022-07-06T17:30:13+00:00","description":"Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"Unauthenticated Remote Code Execution in Roxy-wi","updated":"2025-04-23T15:49:00.662000+00:00","vendors":[],"vulnrichment_repo_path":"2022/31xxx/CVE-2022-31126.json","weaknesses":[]}}