PT-2026-34836 · Roxy-Wi · Roxy-Wi

Firebasky

·

Published

2026-04-24

·

Updated

2026-04-25

·

CVE-2026-33208

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Roxy-WI versions prior to 8.2.6.4
Description The '/config//find-in-config' endpoint fails to sanitize the words parameter before embedding it into a shell command string executed on a remote managed server via SSH. An authenticated attacker can inject shell metacharacters to bypass the intended grep command and execute arbitrary OS commands with sudo privileges, leading to Remote Code Execution (RCE), which is the ability to execute any command on a target machine remotely.
Recommendations Update to version 8.2.6.4.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33208

Affected Products

Roxy-Wi