How to find Control Web Panel (CWP) instances
ID: a837b351-b327-57f2-9fb0-957f2aa4a486
STIX ID: report--a837b351-b327-57f2-9fb0-957f2aa4a486
Feed Name: runZero Blog
Threat Score
A critical (CVSS 9.0) authentication bypass and OS command injection in Control Web Panel (CVE-2025-48703) allows unauthenticated attackers who know a non-root username to execute arbitrary OS commands via the file-permission change feature; the flaw is being actively exploited and affects CWP versions prior to 0.9.8.1205, so administrators should upgrade to 0.9.8.1205 or later immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
