Command injection in Roxy-WI - CVE-2026-33208
Published: April 23, 2026
Roxy-WI
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary os commands.
The vulnerability exists due to command injection in the /config/
Successful exploitation occurs on the remote managed server and the injected commands are executed with sudo privileges.