Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-48703

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.662
EPSS Ranking 98.4%
CVSS Severity
CVSS v3 Score 9.0
Proposed Action
CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
Ransomware Campaign
Unknown
Products affected by CVE-2025-48703


Contact Us

Shodan ® - All rights reserved