ZeroHour

CVE-2025-48703

KEV PoC large

Unauthenticated OS Command Injection RCE in CWP Control Web Panel

CISA: CWP Control Web Panel OS Command Injection Vulnerability

CVSS 3.1
9.0 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CWP (Control Web Panel, also known as CentOS Web Panel) versions before 0.9.8.1205 contain an unauthenticated OS command injection flaw (CWE-78): shell metacharacters supplied in the t_total parameter of a filemanager changePerm request are passed to a shell and executed by the server. The only precondition is knowing a valid non-root username on the target, which raises attack complexity but can be trivially met through exposed or common account names. Successful exploitation yields remote code execution on the hosting server, and the scope-changed CVSS metric (S:C with C:H/I:H/A:H) indicates impact beyond the vulnerable component. Any CWP installation running a version earlier than 0.9.8.1205 is affected — typically internet-facing CentOS/RHEL/AlmaLinux servers run by small hosting providers, resellers, and administrators. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-04, a public proof of concept is available, and EPSS assigns a 99.7% probability of exploitation within 30 days.

What to do: Upgrade to CWP 0.9.8.1205 or later using the panel's built-in update process, as required by CISA's KEV/BOD 22-01 guidance; until patched, restrict access to the CWP admin ports (2030/2031) to trusted IPs or a VPN and limit exposed usernames, since the attacker must know a valid non-root user. Review logs for filemanager changePerm requests containing metacharacters in the t_total parameter to detect exploitation attempts, and check for signs of post-exploitation such as unexpected processes, cron entries, or web shells.

Affected
control-webpanel CWP Control Web Panel (CentOS Web Panel)all versions before 0.9.8.1205
Estimated exposure
large≈ tens of thousands of internet-exposed CWP servers — CWP is a widely used free hosting control panel on small hosting/VPS servers, and public internet scans of its default admin ports (2030/2031) indicate exposure on the order of tens of thousands of hosts; no official install count is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CISA Known Exploited Vulnerability
Affected
CWP Control Web Panel
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
control-webpanel
Products
webpanel
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news