S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 22, 2025

CVE-2022-31161 Scanner

CVE-2022-31161 Scanner - Remote Code Execution vulnerability in Roxy-WI

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.2k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-31161
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Version 6.1.1.0 contains a patch for this issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
roxy-wiby hap-wi
< 6.1.1.0
Updated Aug 22, 2026View on NVD →
Detail

Roxy-WI is an interface for managing the HAProxy, Nginx, and Keepalived services. Used by network administrators and DevOps engineers, it allows for efficient and reliable deployment and management of network services. The system supports scalability and automation, serving enterprises that require robust network management solutions. Roxy-WI is valued for its intuitive UI, enhanced monitoring capabilities, and accessibility over web browsers. It enables teams to configure, monitor, and manage network infrastructure remotely and efficiently. As a widely used tool, maintaining its security becomes paramount to prevent unauthorized access and exploitation.

The Remote Code Execution (RCE) vulnerability in Roxy-WI allows attackers to execute arbitrary code on the affected system. It arises due to insufficient input validation in the application's codebase. Attackers can inject arbitrary OS commands through the delcert parameter without proper input checks. This form of exploitation represents a severe threat as it potentially compromises system integrity. If successfully exploited, attackers can gain remote control over the server, leading to unauthorized data access or disruptions in service. Given its critical nature, immediate remediation is essential to safeguard affected systems.

This vulnerability is located in the /app/options.py file and involves the delcert parameter. Attackers can exploit this endpoint using specially crafted requests to inject arbitrary commands. Without proper validation and sanitation of input parameters, this becomes a gateway for executing harmful commands on the system. The attack payload typically involves modifying HTTP requests to include the injected code within legal parameters. Detection requires scrutinizing HTTP interactions and analyzing anomalous requests containing suspicious command patterns. The risk is exacerbated in environments where Roxy-WI spans multiple critical network services.

The potential effects of exploiting this RCE vulnerability are profound and damaging. An attacker who successfully exploits the vulnerability could execute any command on the server, leading to unauthorized data breaches. Furthermore, it offers the ability to install malware, modify or delete data, and possibly escalate privileges for further exploitation. The breach of Roxy-WI can result in service downtime and consequential financial and reputational damage. It poses a threat to the confidentiality, integrity, and availability of the systems it manages. Organizations using Roxy-WI must urgently apply security patches to mitigate these threats.

REFERENCES

Solution Advice
  • Upgrade Roxy-WI to version 6.1.1.0 or later to patch the vulnerability.
  • Implement strict input validation to prevent command injection exploits.
  • Regularly audit and monitor server logs for any anomalous command patterns.
  • Employ network security tools to detect and capture malicious traffic aimed at Roxy-WI.
  • Train administrators and developers on secure coding practices to prevent similar vulnerabilities in the future.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-31161 Scanner - Remote Code Execution vulnerability in Roxy-WI | S4E