CVE-2025-48703

9.5 CISA KEV

CWP · Control Web Panel

Control Web Panel contains an OS command injection vulnerability in the filemanager component that allows unauthenticated remote code execution.

Executive summary

Control Web Panel versions prior to 0.9.8.1205 are vulnerable to unauthenticated remote code execution, a flaw that is currently being actively exploited in the wild.

Vulnerability

This vulnerability involves improper neutralization of special elements used in an OS command (CWE-78). Attackers can trigger remote code execution via shell metacharacters injected into the t_total parameter within a filemanager changePerm request, provided they have knowledge of a valid non-root username.

Business impact

The ability for an unauthenticated attacker to achieve remote code execution poses a severe risk to the confidentiality, integrity, and availability of the host server. With a CVSS score of 9.5, this vulnerability represents a critical threat, potentially allowing full system compromise, data theft, and the deployment of malicious payloads within the administrative environment.

Remediation

Immediate Action: Update CWP Control Web Panel to version 0.9.8.1205 or later immediately to resolve the command injection flaw.

Proactive Monitoring: Monitor server access logs for unusual requests to the filemanager endpoint and review system process lists for unauthorized shell execution patterns.

Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to filter shell metacharacters from incoming HTTP requests, specifically targeting the t_total parameter.

Exploitation status

Public Exploit Available: Yes — multiple public proof-of-concept repositories exist on GitHub.

Analyst recommendation

Given the critical severity of this vulnerability and the confirmed active exploitation in the wild, organizations must prioritize patching their CWP installations immediately. Failure to apply the update leaves systems exposed to complete remote compromise. If patching is not immediately feasible, restrict access to the web management interface to trusted internal networks only until the update can be applied.

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief kev section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Published in the daily brief kev section
  23. Published in the daily brief kev section
  24. Published in the daily brief kev section
  25. Analyst report written
  26. Fix documented version 0.9.8.1205 per CVE record

Sources