← Vulnerability feed

Vulnerability record · CVE-2022-31137 · published 8 July 2022

CVE-2022-31137: Roxy-WI unauthenticated OS command injection in options.py

Roxy Wi · Roxy Wi

Roxy-WI versions before 6.1.1.0 pass user-supplied input into the subprocess_execute function in /app/options.py without sanitisation, allowing OS command injection. Because the endpoint is reachable without authentication, any network attacker who can reach the interface can run arbitrary system commands on the host.

9.8 CVSS 3.1 Critical EPSS 91% · top 0.2% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a CVSS score of 9.8 and very high EPSS probability makes this an urgent patch target.

What it is

Roxy-WI versions before 6.1.1.0 pass user-supplied input into the subprocess_execute function in /app/options.py without sanitisation, allowing OS command injection. Because the endpoint is reachable without authentication, any network attacker who can reach the interface can run arbitrary system commands on the host.

Impact

An unauthenticated attacker gains remote code execution with the privileges of the Roxy-WI service, allowing full compromise of the managed HAProxy, Nginx, Apache and Keepalived infrastructure and the host itself.

Attack surface

Reached over the network via the Roxy-WI web interface, specifically the code path in /app/options.py that calls subprocess_execute. The CVSS vector (AV:N/AC:L/PR:N/UI:N) and the advisory confirm no authentication and no user interaction are required.

Exploitation

Public exploit code is referenced on Packet Storm and the EPSS score is very high (0.904, 99.8th percentile), indicating active interest, though the CVE is not listed in CISA KEV.

What to do

  • Upgrade Roxy-WI to 6.1.1.0 or later, which contains the fix commit 82666df1e60c45dd6aa533b01a392f015d32f755.
  • If immediate upgrade is not possible, restrict network access to the Roxy-WI interface to trusted management networks only; the vendor states there are no known workarounds.
  • Run the Roxy-WI service under a low-privileged account with no unnecessary sudo or shell access to limit command execution impact.
  • Place the interface behind an authenticating reverse proxy or VPN so unauthenticated requests cannot reach /app/options.py.
  • Monitor the host for unexpected child processes spawned by the Roxy-WI service account.

Detection

  • Audit Roxy-WI web logs for requests to /app/options.py and related endpoints from untrusted source IPs.
  • Monitor process creation on Roxy-WI hosts for shell or command interpreters spawned by the web service user.
  • Alert on outbound network connections from Roxy-WI hosts to unusual destinations, which may indicate post-exploitation.
  • Check for unexpected changes to HAProxy, Nginx, Apache or Keepalived configuration files managed by Roxy-WI.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-31137 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-31161Roxy-wi command injection vulnerabilityRoxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via t…EPSS 28%9.8CVE-2022-31125Roxy-wi improper authentication vulnerabilityRoxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unaut…EPSS 20%9.8CVE-2022-31126Roxy-wi unauthenticated remote code execution via options.py injectionRoxy-wi, an open source web interface for managing HAProxy, Nginx, Apache and Keepalived, contains an injection flaw (CWE-74) in /app/options.py. A r…EPSS 53%analysed9.8CVE-2021-38167Roxy-wi sql injection vulnerabilityRoxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.EPSS 1.3%8.9CVE-2026-33076Roxy-wi path traversal vulnerabilityRoxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface p…EPSS 1.0%8.9CVE-2026-33078Roxy-wi sql injection vulnerabilityRoxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability i…EPSS 0.52%8.8CVE-2026-27811Roxy-wi command injection vulnerabilityRoxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a command injection vulnerability ex…EPSS 3.0%8.8CVE-2024-43804Roxy-wi os command injection vulnerabilityRoxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2022-31137), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.