VDB

CVE-2025-48703

CVE-2025-48703 PUBLISHED KEV CVSS 9 CRITICAL

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

EPSS 99.66% · 99.9th percentile

Risk Scores

CVSS 3.1
9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
99.66%
99.9th percentile

Affected Products

VendorProductVersions
centos-webpanelcentos_web_panel0
control-webpanelwebpanel0
centos-webpanelCentOS Web Panel0

Timeline

  • CVE Published
  • Jan 6, 2023 VulnCheck XDB Entry
  • Jan 11, 2023 VulnCheck KEV Exploitation
  • Feb 11, 2023 VulnCheck XDB Entry
  • Mar 27, 2023 VulnCheck XDB Entry
  • May 2, 2023 VulnCheck KEV Exploitation
  • Aug 17, 2023 VulnCheck KEV Exploitation
  • Nov 18, 2023 VulnCheck XDB Entry
  • Dec 20, 2023 VulnCheck XDB Entry
  • Dec 20, 2023 VulnCheck XDB Entry
  • Feb 27, 2024 VulnCheck XDB Entry
  • May 21, 2024 VulnCheck KEV Exploitation
Open in Interactive Console →
$ Console Community · 100/wk Open console ›