PT-2026-48436 · Roxy-Wi · Roxy-Wi

CVE-2026-45556

·

Published

2026-06-10

·

Updated

2026-06-10

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Roxy-WI versions prior to 8.2.6.5
Description An issue exists in the web interface where the endpoint "POST /waf///rule//save" accepts a config file name form field that is passed to the config mod.master slave upload and restart() function as the destination path. The validation process only checks if the path contains specific service substrings (nginx, haproxy, apache2, httpd, or keepalived) and the substring "conf" or "cfg", while ensuring it does not contain "..". Because an encoded-slash substitution (92 to /) occurs before these checks, an attacker can specify any absolute path on the load balancer filesystem that meets these constraints. The content of the config form field is then written verbatim to that path. This allows an attacker to create files in sensitive directories, such as /etc/cron.d/, leading to remote code execution as root on managed load balancers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Path traversal

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45556
GHSA-85GM-773V-X7M4

Affected Products

Roxy-Wi