Junglewise Threat Intelligence

CVE-2025-34429: LXware 1Panel CSRF in web port configuration

CVE-2025-34429 · Severity: high · CVSS 7.1 · Published 2025-12-10

Technologies: LXware 1Panel, github.com/1Panel-dev/1Panel (Go). Vendors: Go.

Executive brief

1Panel, an open-source control panel used to manage Linux servers and Docker containers, contains a security flaw in its web configuration settings. An attacker could trick an authenticated administrator into visiting a malicious website that silently changes the network port the control panel uses. This can result in a total loss of access for the legitimate administrator, causing service disruption and potentially exposing the management interface on an unintended network port.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in 1Panel versions 1.10.33 - 2.0.15 due to a lack of anti-CSRF defenses on the port-change endpoint. The application fails to implement anti-CSRF tokens or validate Origin/Referer headers for sensitive configuration requests. An unauthenticated remote attacker can craft a malicious webpage that, when visited by an authenticated administrator, triggers a background request to change the web service's listening port. This results in a denial of service (DoS) as the original port becomes inaccessible and may expose the management interface on a port of the attacker's choosing. As of the advisory date, the maintainer has not addressed this vulnerability.

Affected products

  • LXware 1Panel 1.10.33 - 2.0.15

Timeline

  • 2025-12-10: advisory: Advisory published by VulnCheck

References

Related threats