EXPOSURES › CVE-2025-48703
CVE-2025-48703
HIGH ⌖ ON CISA KEV · EXPLOITEDCWP Control Web Panel OS Command Injection Vulnerability exploited unpatched
CWP Control Web Panel, a web hosting management panel, had an OS command injection vulnerability that allowed unauthenticated remote code execution. An attacker could exploit this to execute arbitrary commands on the server via a shell metacharacter in the t_total parameter of a filemanager changePerm request, requiring a valid non-root username.
Shame score — Unpatched vulnerability allowing remote code execution with a valid non-root username.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.