hap-wi vendor intelligence
hap-wi Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting hap-wi products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 3
- Known exploited vulnerabilities affecting hap-wi products
- In CISA KEV
- 0
- Records also listed in the official catalog
- Beyond CISA KEV
- 3
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- hap-wi KEVs with sensor-observed exploitation activity
The catalog gap matters for hap-wi exposure
Three of the three exploited hap-wi CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 100% of this vendor portfolio.
- 0%
- Covered by CISA
- 100%
- Beyond CISA
- 1
- Product families
Attested hap-wi CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2022-31126
Unauthenticated Remote Code Execution in Roxy-wi |
roxy-wi | High | Beyond CISA | 08 Dec 2025 |
|
CVE-2022-31137
Unauthenticated Remote Code Execution in Roxy-WI |
roxy-wi | High | Beyond CISA | 08 Nov 2025 |
|
CVE-2022-31161
Roxy-WI Vulnerable to Unauthenticated Remote Code Execution via ssl_cert Upload |
roxy-wi | High | Beyond CISA | 18 Sep 2025 |
No hap-wi CVEs match this search or filter.
Showing 3 of 3 hap-wi known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, neutralization, and neutralization account for three mapped occurrences across this hap-wi KEV portfolio.
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-94
Improper Control of Generation of Code ('Code Injection')
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.