Vulnerability record · CVE-2022-31137 · published 8 July 2022
CVE-2022-31137: Roxy-WI unauthenticated OS command injection in options.py
Roxy Wi · Roxy Wi
Roxy-WI versions before 6.1.1.0 pass user-supplied input into the subprocess_execute function in /app/options.py without sanitisation, allowing OS command injection. Because the endpoint is reachable without authentication, any network attacker who can reach the interface can run arbitrary system commands on the host.
Description
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a CVSS score of 9.8 and very high EPSS probability makes this an urgent patch target.
What it is
Roxy-WI versions before 6.1.1.0 pass user-supplied input into the subprocess_execute function in /app/options.py without sanitisation, allowing OS command injection. Because the endpoint is reachable without authentication, any network attacker who can reach the interface can run arbitrary system commands on the host.
Impact
An unauthenticated attacker gains remote code execution with the privileges of the Roxy-WI service, allowing full compromise of the managed HAProxy, Nginx, Apache and Keepalived infrastructure and the host itself.
Attack surface
Reached over the network via the Roxy-WI web interface, specifically the code path in /app/options.py that calls subprocess_execute. The CVSS vector (AV:N/AC:L/PR:N/UI:N) and the advisory confirm no authentication and no user interaction are required.
Exploitation
Public exploit code is referenced on Packet Storm and the EPSS score is very high (0.904, 99.8th percentile), indicating active interest, though the CVE is not listed in CISA KEV.
What to do
- Upgrade Roxy-WI to 6.1.1.0 or later, which contains the fix commit 82666df1e60c45dd6aa533b01a392f015d32f755.
- If immediate upgrade is not possible, restrict network access to the Roxy-WI interface to trusted management networks only; the vendor states there are no known workarounds.
- Run the Roxy-WI service under a low-privileged account with no unnecessary sudo or shell access to limit command execution impact.
- Place the interface behind an authenticating reverse proxy or VPN so unauthenticated requests cannot reach /app/options.py.
- Monitor the host for unexpected child processes spawned by the Roxy-WI service account.
Detection
- Audit Roxy-WI web logs for requests to /app/options.py and related endpoints from untrusted source IPs.
- Monitor process creation on Roxy-WI hosts for shell or command interpreters spawned by the web service user.
- Alert on outbound network connections from Roxy-WI hosts to unusual destinations, which may indicate post-exploitation.
- Check for unexpected changes to HAProxy, Nginx, Apache or Keepalived configuration files managed by Roxy-WI.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-31137 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-31137), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.