Alert: Hackers Actively Exploiting Critical "Control Web Panel" RCE Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-44877 | Remote OS Command Injection in CWP Control Web Panel CWP Control Web Panel (formerly CentOS Web Panel), a free hosting control panel used on CentOS/RHEL servers, contains an OS command injection flaw (CWE-78) in its handling of the login parameter. Because user-supplied login input reaches a shell without proper escaping, a remote attacker can submit shell metacharacters and have arbitrary operating-system commands executed on the hosting server. Successful exploitation yields command execution with the privileges of the panel (typically root-level on hosted servers), enabling full server takeover, data theft, or follow-on malware deployment. Any deployment running CWP Control Web Panel is affected, with the highest risk on servers whose panel login interface is reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-01-17 and carries the maximum EPSS score (100% probability of exploitation within 30 days, 100th percentile), indicating active exploitation; no public PoC is known, the ransomware link is unconfirmed, and CVSS has not yet been scored. Do: Update CWP Control Web Panel to the latest release per vendor instructions, consistent with the CISA KEV required action, and verify the patched build is running on every web-facing server. Until patched, restrict access to the CWP panel interface to trusted source IPs at the firewall and review logs for login requests containing shell metacharacters. As a KEV entry added 2023-01-17, federal agencies are required to remediate within the BOD 22-01 two-week window. | 9.8 | 100% | KEV PoC ×6 |
| largeon the order of 10,000-100,000 internet-exposed CWP servers |
Full article292 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJan 12, 2023Server Security / Linux
Malicious actors are actively attempting to exploit a recently patched critical vulnerability in Control Web Panel (CWP) that enables elevated privileges and unauthenticated remote code execution (RCE) on susceptible servers.
Tracked as CVE-2022-44877 (CVSS score: 9.8), the bug impacts all versions of the software before 0.9.8.1147 and was patched by its maintainers on October 25, 2022.
Control Web Panel, formerly known as CentOS Web Panel, is a popular server administration tool for enterprise-based Linux systems.
"login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter," according to NIST.
Gais Security researcher Numan Turle has been credited with discovering and reporting the flaw to the Control Web Panel developers.
Exploitation of the flaw is said to have commenced on January 6, 2023, following the availability of a proof-of-concept (PoC), the Shadowserver Foundation and GreyNoise disclosed.
"This is an unauthenticated RCE," Shadowserver said in a series of tweets, adding, "exploitation is trivial."
GreyNoise said that it has observed four unique IP addresses attempting to exploit CVE-2022-44877 to date, two of which are located in the U.S. and one each from the Netherlands and Thailand.
In light of active exploitation in the wild, users reliant on the software are advised to apply the patches to mitigate potential threats.
This is not the first time similar flaws have been discovered in CWP. In January 2022, two critical issues were identified in the hosting panel that could have been weaponized to achieve pre-authenticated remote code execution.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/01/alert-hackers-actively-exploiting.html