logo

How to find Control Web Panel (CWP) instances

ID: a837b351-b327-57f2-9fb0-957f2aa4a486

STIX ID: report--a837b351-b327-57f2-9fb0-957f2aa4a486

Feed Name: runZero Blog

Threat Score
88/100

Date Published: 2022-01-26

Date Updated: 2026-04-29

Author: Pearce Barry

...
...

A critical (CVSS 9.0) authentication bypass and OS command injection in Control Web Panel (CVE-2025-48703) allows unauthenticated attackers who know a non-root username to execute arbitrary OS commands via the file-permission change feature; the flaw is being actively exploited and affects CWP versions prior to 0.9.8.1205, so administrators should upgrade to 0.9.8.1205 or later immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.