CVE-2025-48703 — CWP Control Web Panel OS Command Injection Vulnerability
CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
- Severity
- critical
- Product
- CWP Control Web Panel
- Published
- 2025-11-04
- EPSS
- 0.997
- CISA KEV
- Known exploited
- Ransomware
- Known campaign use
References and validation
- https://github.com/search?q=CVE-2025-48703&type=repositories
- https://nvd.nist.gov/vuln/detail/CVE-2025-48703
Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.