{"cve":"CVE-2022-31137","epss":{"score":0.90577},"mitre":{"cpes":[],"created":"2022-07-08T00:00:00+00:00","description":"Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":10,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"cvssV4_0":{}},"mitre_repo_path":"cves/2022/31xxx/CVE-2022-31137.json","references":["http://packetstormsecurity.com/files/167805/Roxy-WI-Remote-Command-Execution.html","http://packetstormsecurity.com/files/171648/Roxy-WI-6.1.0.0-Improper-Authentication-Control.html","http://packetstormsecurity.com/files/171652/Roxy-WI-6.1.1.0-Remote-Code-Execution.html","http://packetstormsecurity.com/files/172547/Roxy-WI-6.1.0.0-Remote-Command-Execution.html","https://github.com/hap-wi/roxy-wi/commit/82666df1e60c45dd6aa533b01a392f015d32f755","https://github.com/hap-wi/roxy-wi/security/advisories/GHSA-53r2-mq99-f532"],"title":"Unauthenticated Remote Code Execution in Roxy-WI","updated":"2025-04-22T17:51:19.004000+00:00","vendors":[],"weaknesses":["CWE-78"]},"nvd":{"cpes":["cpe:2.3:a:roxy-wi:roxy-wi:*:*:*:*:*:*:*:*"],"created":"2022-07-08T20:15:07.980000+00:00","description":"Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.","metrics":{"cvssV2_0":{"score":10.0,"vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C"},"cvssV3_0":{},"cvssV3_1":{"score":10.0,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2022/CVE-2022-31137.json","references":["http://packetstormsecurity.com/files/167805/Roxy-WI-Remote-Command-Execution.html","http://packetstormsecurity.com/files/171648/Roxy-WI-6.1.0.0-Improper-Authentication-Control.html","http://packetstormsecurity.com/files/171652/Roxy-WI-6.1.1.0-Remote-Code-Execution.html","http://packetstormsecurity.com/files/172547/Roxy-WI-6.1.0.0-Remote-Command-Execution.html","https://github.com/hap-wi/roxy-wi/commit/82666df1e60c45dd6aa533b01a392f015d32f755","https://github.com/hap-wi/roxy-wi/security/advisories/GHSA-53r2-mq99-f532"],"title":null,"updated":"2026-06-17T04:44:52.990000+00:00","vendors":["roxy-wi","roxy-wi$PRODUCT$roxy-wi"],"weaknesses":["CWE-78"]},"opencve":{"changes":[{"created":"2025-04-22T18:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"0057fce5-ffb5-4142-976d-4da06be9364d"},{"created":"2025-07-14T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.93997},"old":{"score":0.93971}}}},"type":"metrics"}],"id":"34c9ae58-8d5c-4245-82e4-4a9ffc15d06b"}],"cpes":{"data":["cpe:2.3:a:roxy-wi:roxy-wi:*:*:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2022-07-08T00:00:00+00:00","provider":"mitre"},"description":{"data":"Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{"score":10.0,"vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C"},"provider":"nvd"},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":10,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"provider":"mitre"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.90577},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["http://packetstormsecurity.com/files/167805/Roxy-WI-Remote-Command-Execution.html","http://packetstormsecurity.com/files/171648/Roxy-WI-6.1.0.0-Improper-Authentication-Control.html","http://packetstormsecurity.com/files/171652/Roxy-WI-6.1.1.0-Remote-Code-Execution.html","http://packetstormsecurity.com/files/172547/Roxy-WI-6.1.0.0-Remote-Command-Execution.html","https://github.com/hap-wi/roxy-wi/commit/82666df1e60c45dd6aa533b01a392f015d32f755","https://github.com/hap-wi/roxy-wi/security/advisories/GHSA-53r2-mq99-f532"],"providers":["mitre","nvd"]},"title":{"data":"Unauthenticated Remote Code Execution in Roxy-WI","provider":"mitre"},"updated":{"data":"2025-04-22T17:51:19.004000+00:00","provider":"mitre"},"vendors":{"data":["roxy-wi","roxy-wi$PRODUCT$roxy-wi"],"providers":["nvd"]},"weaknesses":{"data":["CWE-78"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2022-07-08T00:00:00+00:00","description":"Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"poc","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":"Unauthenticated Remote Code Execution in Roxy-WI","updated":"2025-04-22T15:37:18.546000+00:00","vendors":[],"vulnrichment_repo_path":"2022/31xxx/CVE-2022-31137.json","weaknesses":[]}}