PT-2026-33845 · Roxy-Wi · Roxy-Wi
Published
2026-04-20
·
Updated
2026-04-21
·
CVE-2026-33431
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Roxy-WI versions prior to 8.2.6.4
Description
The POST '/config//show' API endpoint accepts a
configver parameter that is appended to a base directory path to create a local file path. Because the path traversal guard ignores the user-supplied configver value, an authenticated attacker can use ../ sequences to escape the intended directory and read arbitrary files accessible to the web application process.Recommendations
Update to version 8.2.6.4.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Roxy-Wi