CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://fenrisk.com/rce-centos-webpanel |     | 
History
                    Mon, 22 Sep 2025 10:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Centos-webpanel Centos-webpanel centos Web Panel | |
| Vendors & Products | Centos-webpanel Centos-webpanel centos Web Panel | 
Fri, 19 Sep 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Fri, 19 Sep 2025 18:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known. | |
| Weaknesses | CWE-78 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2025-09-19T00:00:00.000Z
Updated: 2025-09-19T18:41:11.630Z
Reserved: 2025-05-23T00:00:00.000Z
Link: CVE-2025-48703
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-09-19T18:40:53.939Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-09-19T18:15:36.620
Modified: 2025-09-22T21:23:01.543
Link: CVE-2025-48703
 Redhat
                        Redhat
                    No data.