PT-2025-2015 · Roxy-Wi · Roxy-Wi

Slash0X99

·

Published

2025-01-03

·

Updated

2025-01-03

·

CVE-2024-13129

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Roxy-WI versions up to 8.1.3
Description A critical issue has been found in Roxy-WI, affecting the action service function of the file app/modules/roxywi/roxy.py. The manipulation of the action/service argument leads to os command injection. This issue can be exploited remotely. The exploit has been publicly disclosed and may be used.
Recommendations For Roxy-WI versions up to 8.1.3, upgrade to version 8.1.4 to address this issue. As a temporary workaround, consider restricting access to the action service function until the update is applied.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-13129

Affected Products

Roxy-Wi