ZeroHour

Vulnerabilities

85 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-48703
Unauthenticated OS Command Injection RCE in CWP Control Web Panel

CWP (Control Web Panel, also known as CentOS Web Panel) versions before 0.9.8.1205 contain an unauthenticated OS command injection flaw (CWE-78): shell metacharacters supplied in the t_total parameter of a filemanager changePerm request are passed to a shell and executed by the server. The only precondition is knowing a valid non-root username on the target, which raises attack complexity but can be trivially met through exposed or common account names. Successful exploitation yields remote code execution on the hosting server, and the scope-changed CVSS metric (S:C with C:H/I:H/A:H) indicates impact beyond the vulnerable component. Any CWP installation running a version earlier than 0.9.8.1205 is affected — typically internet-facing CentOS/RHEL/AlmaLinux servers run by small hosting providers, resellers, and administrators. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-04, a public proof of concept is available, and EPSS assigns a 99.7% probability of exploitation within 30 days.

Do: Upgrade to CWP 0.9.8.1205 or later using the panel's built-in update process, as required by CISA's KEV/BOD 22-01 guidance; until patched, restrict access to the CWP admin ports (2030/2031) to trusted IPs or a VPN and limit exposed usernames, since the attacker must know a valid non-root user. Review logs for filemanager changePerm requests containing metacharacters in the t_total parameter to detect exploitation attempts, and check for signs of post-exploitation such as unexpected processes, cron entries, or web shells.

9.0100% KEV PoC
  • control-webpanel CWP Control Web Panel (CentOS Web Panel) all versions before 0.9.8.1205
large≈ tens of thousands of internet-exposed CWP servers
CVE-2023-42121
+3 in the same advisory: …42120 …42123 …42122
Control Web Panel Missing Authentication Remote Code Execution Vulnerability.

Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of authentication within the web interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of a valid CWP user. Was ZDI-CAN-20582.

NVD description · AI analysis pending
9.8
group max
1%
  • control-webpanel webpanel
CVE-2022-44877
Remote OS Command Injection in CWP Control Web Panel

CWP Control Web Panel (formerly CentOS Web Panel), a free hosting control panel used on CentOS/RHEL servers, contains an OS command injection flaw (CWE-78) in its handling of the login parameter. Because user-supplied login input reaches a shell without proper escaping, a remote attacker can submit shell metacharacters and have arbitrary operating-system commands executed on the hosting server. Successful exploitation yields command execution with the privileges of the panel (typically root-level on hosted servers), enabling full server takeover, data theft, or follow-on malware deployment. Any deployment running CWP Control Web Panel is affected, with the highest risk on servers whose panel login interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-01-17 and carries the maximum EPSS score (100% probability of exploitation within 30 days, 100th percentile), indicating active exploitation; no public PoC is known, the ransomware link is unconfirmed, and CVSS has not yet been scored.

Do: Update CWP Control Web Panel to the latest release per vendor instructions, consistent with the CISA KEV required action, and verify the patched build is running on every web-facing server. Until patched, restrict access to the CWP panel interface to trusted source IPs at the firewall and review logs for login requests containing shell metacharacters. As a KEV entry added 2023-01-17, federal agencies are required to remediate within the BOD 22-01 two-week window.

9.8100% KEV PoC ×6
  • CWP Control Web Panel (formerly CentOS Web Panel)
largeon the order of 10,000-100,000 internet-exposed CWP servers
CVE-2021-45467
+1 in the same advisory: …45466
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arb

In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be used, e.g., .%00%00%00./.%00%00%00./api/account_new_create could also be used for the scripts parameter.

NVD description · AI analysis pending
9.871% PoC
  • control-webpanel webpanel
CVE-2022-25046
+2 in the same advisory: …25048 …25047
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.

A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.

NVD description · AI analysis pending
9.8
group max
58% PoC
  • control-webpanel webpanel
CVE-2021-31324
+1 in the same advisory: …31316
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.

The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.

NVD description · AI analysis pending
9.835% PoC
  • control-webpanel webpanel
CVE-2020-15612
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923.

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_ftp_manager.php. When parsing the userLogin parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-9737.

NVD description · AI analysis pending
9.8
group max
8%
  • control-webpanel webpanel