CVE-2025-48703
9.5 CISA KEVCWP · Control Web Panel
Control Web Panel contains an OS command injection vulnerability in the filemanager component that allows unauthenticated remote code execution.
Executive summary
Control Web Panel versions prior to 0.9.8.1205 are vulnerable to unauthenticated remote code execution, a flaw that is currently being actively exploited in the wild.
Vulnerability
This vulnerability involves improper neutralization of special elements used in an OS command (CWE-78). Attackers can trigger remote code execution via shell metacharacters injected into the t_total parameter within a filemanager changePerm request, provided they have knowledge of a valid non-root username.
Business impact
The ability for an unauthenticated attacker to achieve remote code execution poses a severe risk to the confidentiality, integrity, and availability of the host server. With a CVSS score of 9.5, this vulnerability represents a critical threat, potentially allowing full system compromise, data theft, and the deployment of malicious payloads within the administrative environment.
Remediation
Immediate Action: Update CWP Control Web Panel to version 0.9.8.1205 or later immediately to resolve the command injection flaw.
Proactive Monitoring: Monitor server access logs for unusual requests to the filemanager endpoint and review system process lists for unauthorized shell execution patterns.
Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to filter shell metacharacters from incoming HTTP requests, specifically targeting the t_total parameter.
Exploitation status
Public Exploit Available: Yes — multiple public proof-of-concept repositories exist on GitHub.
Analyst recommendation
Given the critical severity of this vulnerability and the confirmed active exploitation in the wild, organizations must prioritize patching their CWP installations immediately. Failure to apply the update leaves systems exposed to complete remote compromise. If patching is not immediately feasible, restrict access to the web management interface to trusted internal networks only until the update can be applied.
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Analyst report written
- Fix documented version 0.9.8.1205 per CVE record