This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: Roxy-WI < 6.1.1.0 suffers from **Command Injection**. ๐ **Consequences**: Attackers can execute arbitrary OS commands remotely via the `subprocess_execute` function. This leads to full server compromise.
Q2Root Cause? (CWE/Flaw)
๐ก๏ธ **Root Cause**: **CWE-77** (Command Injection). The flaw lies in the `/app/options.py` file.โฆ
๐ข **Affected**: **Roxy-WI** versions **before 6.1.1.0**. ๐ฆ **Vendor**: hap-wi. ๐ **Component**: The web interface used to manage Haproxy, Nginx, and Keepalived servers.
Q4What can hackers do? (Privileges/Data)
๐ **Capabilities**: Hackers gain **Remote Code Execution (RCE)**. ๐ **Impact**: They can read/write sensitive data, modify configurations, and potentially pivot to other internal systems.โฆ
โก **Threshold**: **LOW**. ๐ซ **Auth**: No authentication required (`PR:N`). ๐ฑ๏ธ **UI**: No user interaction needed (`UI:N`). ๐ **Vector**: Network-based (`AV:N`). This is a critical, easy-to-exploit vulnerability.
Q6Is there a public Exp? (PoC/Wild Exploitation)
๐ **Exploit Status**: **YES**. Public PoC exists via Nuclei templates. ๐ **Reference**: `CVE-2022-31161.yaml` on ProjectDiscovery GitHub. Wild exploitation is highly likely given the low barrier to entry.
Q7How to self-check? (Features/Scanning)
๐ **Self-Check**: Scan for Roxy-WI instances. ๐งช **Test**: Send crafted requests to the `/app/options.py` endpoint targeting the `delcert` parameter.โฆ
โ **Fix**: **YES**. Official patch released in **v6.1.1.0**. ๐ฅ **Action**: Upgrade Roxy-WI immediately to version 6.1.1.0 or later. Check the GitHub release notes for details.
Q9What if no patch? (Workaround)
๐ **No Patch?**: If upgrading isn't possible, **block external access** to the Roxy-WI web interface. ๐ง **Mitigate**: Implement strict WAF rules to filter command injection patterns in the `delcert` parameter.โฆ
๐ฅ **Urgency**: **CRITICAL**. ๐จ **Priority**: **IMMEDIATE ACTION REQUIRED**. CVSS Score indicates High Impact. With no auth required, automated bots are likely scanning for this. Patch now to prevent compromise.