ZeroHour

CVE-2022-44877

KEV PoC ×6large

Remote OS Command Injection in CWP Control Web Panel

CISA: CWP Control Web Panel OS Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CWP Control Web Panel (formerly CentOS Web Panel), a free hosting control panel used on CentOS/RHEL servers, contains an OS command injection flaw (CWE-78) in its handling of the login parameter. Because user-supplied login input reaches a shell without proper escaping, a remote attacker can submit shell metacharacters and have arbitrary operating-system commands executed on the hosting server. Successful exploitation yields command execution with the privileges of the panel (typically root-level on hosted servers), enabling full server takeover, data theft, or follow-on malware deployment. Any deployment running CWP Control Web Panel is affected, with the highest risk on servers whose panel login interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-01-17 and carries the maximum EPSS score (100% probability of exploitation within 30 days, 100th percentile), indicating active exploitation; no public PoC is known, the ransomware link is unconfirmed, and CVSS has not yet been scored.

What to do: Update CWP Control Web Panel to the latest release per vendor instructions, consistent with the CISA KEV required action, and verify the patched build is running on every web-facing server. Until patched, restrict access to the CWP panel interface to trusted source IPs at the firewall and review logs for login requests containing shell metacharacters. As a KEV entry added 2023-01-17, federal agencies are required to remediate within the BOD 22-01 two-week window.

Affected
CWP Control Web Panel (formerly CentOS Web Panel)
Estimated exposure
largeon the order of 10,000-100,000 internet-exposed CWP servers — No published install base exists; public internet scans index tens of thousands of CWP admin panels reachable online, and CWP is a widely deployed free cPanel alternative on CentOS/RHEL VPS hosting, so order-of-magnitude exposure is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.

CISA Known Exploited Vulnerability
Affected
CWP Control Web Panel
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
control-webpanel
Products
webpanel
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news