Skip to content
COOEY

EXPOSURES › CVE-2025-48703

CVE-2025-48703

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-11-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-48703 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

CWP Control Web Panel OS Command Injection Vulnerability exploited unpatched

CWP Control Web Panel, a web hosting management panel, had an OS command injection vulnerability that allowed unauthenticated remote code execution. An attacker could exploit this to execute arbitrary commands on the server via a shell metacharacter in the t_total parameter of a filemanager changePerm request, requiring a valid non-root username.

Shame score — Unpatched vulnerability allowing remote code execution with a valid non-root username.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.