CVE-2025-48703 is a critical remote code execution (RCE) vulnerability (CVSS 9.0) affecting Control Web Panel (CWP) versions prior to 0.9.8.1205. This flaw allows unauthenticated attackers to execute arbitrary commands by injecting shell metacharacters into the 't_total' parameter during a filemanager 'changePerm' request, provided a valid non-root username is known. The vulnerability is actively exploited in the wild, listed on CISA's KEV catalog, and has garnered significant community and media attention, with detection tools like Nuclei templates available. Organizations using affected CWP versions must patch immediately to mitigate the severe risk of complete system compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.8.1205CPE matchmatch criteria | cpe:2.3:a:control-webpanel:webpanel:*:*:*:*:*:*:*:* | ||
>= 0, < 0.9.8.1205CPE match | cpe:2.3:a:centos-webpanel:centos_web_panel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.8 Mastodon, and 2.3 GitHub mentions.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.