roxy-wi CVE Vulnerabilities & Metrics

Focus on roxy-wi vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About roxy-wi Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with roxy-wi. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total roxy-wi CVEs: 12
Earliest CVE date: 07 Aug 2021, 18:15 UTC
Latest CVE date: 29 Aug 2024, 17:15 UTC

Latest CVE reference: CVE-2024-43804

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -75.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -75.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical roxy-wi CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.79

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 6
4.0-6.9 2
7.0-8.9 3
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS roxy-wi CVEs

These are the five CVEs with the highest CVSS scores for roxy-wi, sorted by severity first and recency.

All CVEs for roxy-wi

CVE-2024-43804 roxy-wi vulnerability CVSS: 0 29 Aug 2024, 17:15 UTC

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. An OS Command Injection vulnerability allows any authenticated user on the application to execute arbitrary code on the web application server via port scanning functionality. User-supplied input is used without validation when constructing and executing an OS command. User supplied JSON POST data is parsed and if "id" JSON key does not exist, JSON value supplied via "ip" JSON key is assigned to the "ip" variable. Later on, "ip" variable which can be controlled by the attacker is used when constructing the cmd and cmd1 strings without any extra validation. Then, server_mod.subprocess_execute function is called on both cmd1 and cmd2. When the definition of the server_mod.subprocess_execute() function is analyzed, it can be seen that subprocess.Popen() is called on the input parameter with shell=True which results in OS Command Injection. This issue has not yet been patched. Users are advised to contact the Roxy-WI to coordinate a fix.

CVE-2023-29004 roxy-wi vulnerability CVSS: 0 17 Apr 2023, 19:15 UTC

hap-wi/roxy-wi is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A Path Traversal vulnerability was found in the current version of Roxy-WI (6.3.9.0 at the moment of writing this report). The vulnerability can be exploited via an HTTP request to /app/options.py and the config_file_name parameter. Successful exploitation of this vulnerability could allow an attacker with user level privileges to obtain the content of arbitrary files on the file server within the scope of what the server process has access to. The root-cause of the vulnerability lies in the get_config function of the /app/modules/config/config.py file, which only checks for relative path traversal, but still allows to read files from absolute locations passed via the config_file_name parameter.

CVE-2023-25804 roxy-wi vulnerability CVSS: 0 15 Mar 2023, 18:15 UTC

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a limited path traversal vulnerability. An SSH key can be saved into an unintended location, for example the `/tmp` folder using a payload `../../../../../tmp/test111_dev`. This issue has been fixed in version 6.3.5.0.

CVE-2023-25803 roxy-wi vulnerability CVSS: 0 13 Mar 2023, 20:15 UTC

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a directory traversal vulnerability that allows the inclusion of server-side files. This issue is fixed in version 6.3.5.0.

CVE-2023-25802 roxy-wi vulnerability CVSS: 0 13 Mar 2023, 20:15 UTC

Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `/etc/nginx/../passwd`, allowing an actor to gain information about a server. Version 6.3.6.0 has a patch for this issue.

CVE-2022-31161 roxy-wi vulnerability CVSS: 0 15 Jul 2022, 21:15 UTC

Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Version 6.1.1.0 contains a patch for this issue.

CVE-2022-31137 roxy-wi vulnerability CVSS: 10.0 08 Jul 2022, 20:15 UTC

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2022-31126 roxy-wi vulnerability CVSS: 7.5 06 Jul 2022, 18:15 UTC

Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2022-31125 roxy-wi vulnerability CVSS: 7.5 06 Jul 2022, 18:15 UTC

Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request. This affects Roxywi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2021-38169 roxy-wi vulnerability CVSS: 6.5 07 Aug 2021, 18:15 UTC

Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.

CVE-2021-38168 roxy-wi vulnerability CVSS: 6.5 07 Aug 2021, 18:15 UTC

Roxy-WI through 5.2.2.0 allows authenticated SQL injection via select_servers.

CVE-2021-38167 roxy-wi vulnerability CVSS: 7.5 07 Aug 2021, 18:15 UTC

Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to bypass authentication.