漏洞描述
Roxy-WI before 6.1.1.0 is susceptible to remote code execution. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
packetstormsecurity.comhttp://packetstormsecurity.com/files/167805/Roxy-WI-Remote-Command-Execution.html↗www.cve.orghttps://www.cve.org/CVERecord?id=CVE-2022-31137↗github.comhttps://github.com/hap-wi/roxy-wi/security/advisories/GHSA-mh86-878h-43c9↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-31137↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-31126↗