FAIL › dossier
Control Web Panel
PRODUCT· dossier confidence 90%
Control Web Panel is an IoT/industrial control software vendor with a critically weak security posture, marked by two high-severity, actively exploited OS command injection vulnerabilities in a two-year span, including one that remained unpatched as of late 2025.
PROFILE
CategoryIoT/Industrial Control SoftwareWhat they doControl Web Panel (CWP) is a web-based control panel software for industrial and IoT environments.
SECURITY POSTURE
The security posture is critically weak, evidenced by two high-severity, actively exploited OS command injection vulnerabilities in the Control Web Panel product within a two-year window, with at least one remaining unpatched as of late 2025.
Notable failures
- CVE-2022-44877: Actively exploited OS command injection vulnerability
- CVE-2025-48703: Unpatched OS command injection vulnerability exploited
Patterns: Repeated OS command injection vulnerabilities in the Control Web Panel product; Failure to patch critical vulnerabilities before active exploitation
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-11-04 | CVE-2025-48703 | high | CWP Control Web Panel OS Command Injection Vulnerability exploited unpatched |
| 2023-01-17 | CVE-2022-44877 | high | CWP Control Web Panel OS Command Injection Vulnerability actively exploited |
Open questions: The specific vendor name for Control Web Panel (CWP) · The founding year and headquarters location of the vendor · The total employee count and ownership structure of the vendor
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-16 04:20:51.556135+00:00