Junglewise Threat Intelligence

CVE-2025-48703: Control Web Panel OS command injection in filemanager

CVE-2025-48703 · Severity: critical · CVSS 9 · Exploited in the wild · Published 2025-11-04

Technologies: cPanel Control Web Panel. Vendors: cPanel.

Executive brief

Control Web Panel (formerly CentOS Web Panel) is a popular management interface for web hosting servers. A critical security flaw allows attackers to remotely take control of the server without needing a password, provided they know a valid username on the system. This vulnerability has been observed being used in active attacks, potentially leading to full data theft or service disruption.

Technical details

An OS command injection vulnerability (CWE-78) exists in Control Web Panel (CWP) versions prior to 0.9.8.1205. The flaw is located in the 'changePerm' request of the filemanager component, specifically within the 't_total' parameter. An unauthenticated remote attacker can achieve code execution by injecting shell metacharacters into this parameter. While authentication is not required, the attacker must know a valid non-root username on the target system to successfully trigger the exploit. This vulnerability is confirmed to be exploited in the wild and is mitigated by updating to version 0.9.8.1205 or later.

Affected products

  • Control Web Panel Control Web Panel (CWP) Before 0.9.8.1205

Timeline

  • 2025-09-19: disclosed: Initial CVE publication
  • 2025-11-04: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2025-11-04: exploited: Confirmed active exploitation in the wild

Related threats