Command injection in Roxy-WI - CVE-2022-31161
Published: July 6, 2022 / Updated: April 20, 2026
Roxy-WI
Roxy-WI
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to command injection in the upload function of /app/options.py when handling a specially crafted HTTP request for ssl_cert upload. A remote attacker can send a specially crafted HTTP request to execute arbitrary code.