CWE-CWE-78

CWP (Control Web Panel) < 0.9.8.1205 - Remote Code Execution (CVE-2025-48703)

Severity:
Critical
Summary
CWP (Control Web Panel) versions prior to 0.9.8.1205 contain a critical remote code execution vulnerability (CVE-2025-48703). Shell metacharacters in the t_total parameter of the filemanager changePerm request are not properly sanitized, allowing unauthenticated attackers to execute arbitrary OS commands on the server. Exploitation requires knowledge of a valid non-root username on the system.
Impact
An unauthenticated remote attacker can execute arbitrary commands with the privileges of the CWP web service process, potentially leading to full system compromise. This includes unauthorized access to all hosted websites and databases, credential theft, installation of backdoors or malware, lateral movement to other network systems, and complete service disruption.
Remediation
Immediately upgrade CWP (Control Web Panel) to version 0.9.8.1205 or later.

If immediate patching is not possible, apply the following temporary mitigations:
1. Restrict access to the CWP web interface using firewall rules to allow only trusted IP addresses.
2. Monitor server logs for unexpected outbound connections or unusual process execution from the CWP process.

After patching, review system logs for indicators of compromise and rotate all credentials.
Required Skills for Successful Exploitation
Actions To Take
Classifications
Vulnerability Index

You can search and find all vulnerabilities

Featured resources

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding

Blog

Strengthening enterprise application security: Invicti acquires Kondukto

Blog

Modern AppSec KPIs: Moving from scan counts to real risk reduction

Blog

Friends don’t let friends shift left: Shift smarter with DAST-first AppSec

Blog

Vibe talking: Dan Murphy on the promises, pitfalls, and insecurities of vibe coding