PT-2026-33845 · Roxy-Wi · Roxy-Wi

Published

2026-04-20

·

Updated

2026-04-21

·

CVE-2026-33431

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Roxy-WI versions prior to 8.2.6.4
Description The POST '/config//show' API endpoint accepts a configver parameter that is appended to a base directory path to create a local file path. Because the path traversal guard ignores the user-supplied configver value, an authenticated attacker can use ../ sequences to escape the intended directory and read arbitrary files accessible to the web application process.
Recommendations Update to version 8.2.6.4.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33431

Affected Products

Roxy-Wi