← Vulnerability feed

Vulnerability record · CVE-2024-43804 · published 29 August 2024

CVE-2024-43804: Roxy-wi os command injection vulnerability

Roxy Wi · Roxy Wi

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated user on the application to execute arbitrary code on the web application server via port scanning functionality. User-supplied input is used without validation when constructing and executing an OS command. User supplied JSON POST data is parsed and if "id" JSON key does not exist, JSON value supplied via "ip" JSON key is assigned to the "ip" variable. Later on, "ip" variable which can be controlled by the attacker is used when constructing the cmd and cmd1 strings without any extra validation. Then, server_mod.subprocess_execute function is called on both cmd1 and cmd2. When the definition of the server_mod.subprocess_execute() function is analyzed, it can be seen that subprocess.Popen() is called on the input parameter with shell=True which results in OS Command Injection. This issue has not yet been patched. Users are advised to contact the Roxy-WI to coordinate a fix.

8.8 CVSS 3.1 High EPSS 2.6% · top 15.5% CWE-78 · OS command injection
8.8CVSS 3.1 base score
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated user on the application to execute arbitrary code on the web application server via port scanning functionality. User-supplied input is used without validation when constructing and executing an OS command. User supplied JSON POST data is parsed and if "id" JSON key does not exist, JSON value supplied via "ip" JSON key is assigned to the "ip" variable. Later on, "ip" variable which can be controlled by the attacker is used when constructing the cmd and cmd1 strings without any extra validation. Then, server_mod.subprocess_execute function is called on both cmd1 and cmd2. When the definition of the server_mod.subprocess_execute() function is analyzed, it can be seen that subprocess.Popen() is called on the input parameter with shell=True which results in OS Command Injection. This issue has not yet been patched. Users are advised to contact the Roxy-WI to coordinate a fix.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-43804 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-31161Roxy-wi command injection vulnerabilityRoxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via t…EPSS 28%9.8CVE-2022-31137Roxy-WI unauthenticated OS command injection in options.pyRoxy-WI versions before 6.1.1.0 pass user-supplied input into the subprocess_execute function in /app/options.py without sanitisation, allowing OS co…EPSS 91%analysed9.8CVE-2022-31125Roxy-wi improper authentication vulnerabilityRoxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unaut…EPSS 20%9.8CVE-2022-31126Roxy-wi unauthenticated remote code execution via options.py injectionRoxy-wi, an open source web interface for managing HAProxy, Nginx, Apache and Keepalived, contains an injection flaw (CWE-74) in /app/options.py. A r…EPSS 53%analysed9.8CVE-2021-38167Roxy-wi sql injection vulnerabilityRoxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.EPSS 1.3%8.9CVE-2026-33076Roxy-wi path traversal vulnerabilityRoxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface p…EPSS 1.0%8.9CVE-2026-33078Roxy-wi sql injection vulnerabilityRoxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 8.2.6.4 have a SQL injection vulnerability i…EPSS 0.52%8.8CVE-2026-27811Roxy-wi command injection vulnerabilityRoxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a command injection vulnerability ex…EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2024-43804), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.