CWP Control Web Panel OS Command Injection Vulnerability
centos-webpanel — CentOS Web Panel
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
9.0
99.7%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- High
- Privileges required
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Published
- Sep 19, 2025
- Modified
- Jun 17, 2026
- Added to KEV
- Nov 4, 2025
- Federal patch due
- Nov 25, 2025
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
2 foundWeaponization
Public repositories whose name or description references CVE-2025-48703, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- Skynoxk/CVE-2025-48703★ 3
Remote Code execution in CentOS web panel
updated Jul 8, 2026
- itstarsec/CVE-2025-48703★ 0
CVE-2025-48703 là lỗ hổng mức độ nghiêm trọng trong CentOS Web Panel (CWP) cho phép kẻ tấn công không xác thực (unauthenticated) có thể thực thi mã từ xa (RCE) thông qua bỏ qua cơ chế xác thực và thực thi câu lệnh hệ thống. Lỗ hổng ảnh hưởng CWP từ phiên bản 0.9.8.1204 trở về trước, và đã được vá trên phiên bản mới nhất 0.9.8.1205.
updated Jun 4, 2026
References
How this class of flaw gets exploited
Frequently asked questions
What is CVE-2025-48703?
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
How severe is CVE-2025-48703?
CVE-2025-48703 has a CVSS base score of 9.0 out of 10 (CVSS 3.1).
Is CVE-2025-48703 actively exploited in the wild?
Yes. CVE-2025-48703 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Nov 4, 2025, meaning CISA has confirmed evidence of active exploitation.
What is the EPSS score for CVE-2025-48703?
99.7% - meaning FIRST.org's EPSS model estimates a 99.7% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2025-48703?
Yes - a public Nuclei template referencing CVE-2025-48703 exist in public repositories we checked. We also found 2 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2025-48703?
CVE-2025-48703 is classified under CWE-78 (CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')).
Cross-checked against
Impactr finds and proves whether CVE-2025-48703 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist