Skip to content
COOEY

FAIL › dossier

CWP

VENDOR

· dossier confidence 0%

CWP (Control Web Panel) is a CentOS/RHEL system administration tool with a critically poor security track record. Multiple high-severity RCE vulnerabilities have been actively exploited, including CVE-2022-44877 which was added to CISA's KEV catalog, and CVE-2025-48703 which remained unpatched. The vendor demonstrates a pattern of releasing products with severe, exploitable flaws and failing to patch them before threat actors abuse them.

PROFILE
CategorysoftwareWhat they doCWP (Control Web Panel) is a web-based control panel for CentOS/RHEL systems. It provides system administration and management capabilities.
SECURITY POSTURE

The vendor has a poor security posture, evidenced by multiple high-severity remote code execution (RCE) vulnerabilities in its Control Web Panel product that were actively exploited by threat actors and added to CISA's Known Exploited Vulnerabilities (KEV) catalog.

Notable failures
  • CVE-2022-44877: Active RCE exploitation in CentOS Web Panel
  • CVE-2025-48703: Unpatched OS Command Injection in Control Web Panel
Patterns: Repeated unpatched OS command injection and remote code execution vulnerabilities in web panels; Failure to patch critical vulnerabilities before active exploitation
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2025-11-04 CVE-2025-48703 high CWP Control Web Panel OS Command Injection Vulnerability exploited unpatched
2023-01-17 CVE-2022-44877 high CWP Control Web Panel OS Command Injection Vulnerability actively exploited
Open questions: CWP's official website URL · CWP's founding year · CWP's headquarters location · CWP's organizational size · CWP's ownership structure
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-15 04:04:57.167770+00:00