LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-48703: CWP Control Web Panel OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 4, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 25, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-48703 to its Known Exploited Vulnerabilities catalog on Nov 4, 2025, with a federal patch deadline of Nov 25, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in…

CVE-2025-48703 is an OS command injection vulnerability in CWP Control Web Panel (formerly CentOS Web Panel). It permits unauthenticated remote code execution when an attacker supplies shell metacharacters in the t_total parameter of a filemanager changePerm request, provided a valid non-root username is already known. Servers running this panel are commonly used for web hosting and site management; successful exploitation can give an attacker the ability to run arbitrary operating-system commands under the context of the panel process, leading to full host compromise, data theft, or further lateral movement.

Because the attack requires no authentication beyond knowledge of a legitimate non-root account name, any internet-exposed CWP instance is at elevated risk until the issue is addressed. Confirm all version, configuration, and patch details against the vendor advisory before taking action.

How it works

The vulnerability is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command). In products of this class, user-controlled input is passed to a shell or system command without adequate sanitization or escaping. Here, the t_total parameter in a filemanager changePerm request can contain shell metacharacters that alter the intended command line. An unauthenticated remote attacker who already knows a valid non-root username can craft such a request to inject and execute arbitrary commands on the underlying host. No further authentication is required once the username is known. Exact request format, payload construction, and any additional constraints must be verified from the vendor advisory; do not rely on unconfirmed public proof-of-concept material.

Am I affected? How to find it in your systems

CWP Control Web Panel is typically installed on Linux servers that provide web-hosting control-panel functionality. It commonly exposes a web interface for administrators and end users to manage files, permissions, domains, and services.

If public detail on exact indicators is limited, treat any unexplained command execution or file-permission changes on CWP hosts as suspicious and investigate further.

How to remediate

Apply the vendor-supplied update or mitigation instructions for CVE-2025-48703 as the primary remediation. Follow the CISA-required action: apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for any cloud-hosted instances, or discontinue use of the product if mitigations are unavailable. After patching, restart affected services and verify that the vulnerable code path is no longer reachable.

Additional hardening steps appropriate to this weakness class include:

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not eliminate the vulnerability; schedule patching as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities of this severity frequently lead to breaches in which credentials, website content, customer data, or other sensitive material are taken. If you suspect compromise, isolate the host, preserve logs and memory images, and begin incident-response procedures. As a quick external check, you can run a free exposure scan of your email addresses against known breach data sets to determine whether any associated accounts have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCWP · Control Web Panel
WeaknessCWE-78
Added to CISA KEVNov 4, 2025
Federal patch deadlineNov 25, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities