Roxy wi v6.1.1.0 unauthenticated remote code execution (rce) via ssl_cert upload Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2023-04-03 |
Type : webapps |
Platform : python
This exploit / vulnerability Roxy wi v6.1.1.0 unauthenticated remote code execution (rce) via ssl_cert upload is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# ADVISORY INFORMATION
# Exploit Title: Roxy WI v6.1.1.0 - Unauthenticated Remote Code Execution (RCE) via ssl_cert Upload
# Date of found: 21 July 2022
# Application: Roxy WI <= v6.1.1.0
# Author: Nuri Çilengir
# Vendor Homepage: https://roxy-wi.org
# Software Link: https://github.com/hap-wi/roxy-wi.git
# Advisory: https://pentest.blog/advisory-roxy-wi-unauthenticated-remote-code-executions-cve-2022-31137
# Tested on: Ubuntu 22.04
# CVE : CVE-2022-31161