CVE-2021-31324 describes a critical Command Injection vulnerability within the unprivileged user portal of CentOS Web Panel. This flaw allows an unauthenticated attacker to achieve root Remote Code Execution with low attack complexity. While not currently listed in CISA's KEV catalog or having public Metasploit/ExploitDB modules, Nuclei templates for OS Command Injection exist, and its high EPSS score suggests a significant likelihood of exploitation. Despite its critical nature, there is currently no recorded community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:control-webpanel:webpanel:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.