CVE-2022-44877
KEV PoC ×6largeRemote OS Command Injection in CWP Control Web Panel
CISA: CWP Control Web Panel OS Command Injection Vulnerability
CWP Control Web Panel (formerly CentOS Web Panel), a free hosting control panel used on CentOS/RHEL servers, contains an OS command injection flaw (CWE-78) in its handling of the login parameter. Because user-supplied login input reaches a shell without proper escaping, a remote attacker can submit shell metacharacters and have arbitrary operating-system commands executed on the hosting server. Successful exploitation yields command execution with the privileges of the panel (typically root-level on hosted servers), enabling full server takeover, data theft, or follow-on malware deployment. Any deployment running CWP Control Web Panel is affected, with the highest risk on servers whose panel login interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-01-17 and carries the maximum EPSS score (100% probability of exploitation within 30 days, 100th percentile), indicating active exploitation; no public PoC is known, the ransomware link is unconfirmed, and CVSS has not yet been scored.
What to do: Update CWP Control Web Panel to the latest release per vendor instructions, consistent with the CISA KEV required action, and verify the patched build is running on every web-facing server. Until patched, restrict access to the CWP panel interface to trusted source IPs at the firewall and review logs for login requests containing shell metacharacters. As a KEV entry added 2023-01-17, federal agencies are required to remediate within the BOD 22-01 two-week window.
| CWP Control Web Panel (formerly CentOS Web Panel) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
- Affected
- CWP Control Web Panel
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- control-webpanel
- Products
- webpanel
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H