PT-2026-48436 · Roxy-Wi · Roxy-Wi
CVE-2026-45556
·
Published
2026-06-10
·
Updated
2026-06-10
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Roxy-WI versions prior to 8.2.6.5
Description
An issue exists in the web interface where the endpoint "POST /waf///rule//save" accepts a
config file name form field that is passed to the config mod.master slave upload and restart() function as the destination path. The validation process only checks if the path contains specific service substrings (nginx, haproxy, apache2, httpd, or keepalived) and the substring "conf" or "cfg", while ensuring it does not contain "..". Because an encoded-slash substitution (92 to /) occurs before these checks, an attacker can specify any absolute path on the load balancer filesystem that meets these constraints. The content of the config form field is then written verbatim to that path. This allows an attacker to create files in sensitive directories, such as /etc/cron.d/, leading to remote code execution as root on managed load balancers.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Path traversal
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Roxy-Wi