Missing Authorization in Roxy-WI - CVE-2026-45549
Published: May 16, 2026
Roxy-WI
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to missing authorization in POST /smon/agent/action/<action> when handling crafted POST requests with a user-supplied server_ip value. A remote user can send a specially crafted request to cause a denial of service.
The issue can be exploited by a guest account and affects the roxy-wi-smon-agent systemd unit on a named target host.