Remote Code Execution Vulnerability in Control Web Panel by CWP
CVE-2025-48703

9CRITICAL

Key Information:

Vendor
CVE Published:
19 September 2025

Badges

💰 Ransomware👾 Exploit Exists🟣 EPSS 68%🦅 CISA Reported📰 News Worthy

What is CVE-2025-48703?

A vulnerability exists in Control Web Panel (CWP) that allows unauthenticated remote code execution. This issue arises when shell metacharacters are used in the t_total parameter during a file manager changePerm request. An attacker must possess knowledge of a valid non-root username to exploit this vulnerability effectively. If successfully exploited, it may lead to unauthorized command execution on the server, posing a significant security risk to the affected systems.

CISA has reported CVE-2025-48703

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2025-48703 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.

The CISA's recommendation is: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected Version(s)

CentOS Web Panel 0 < 0.9.8.1205

News Articles

Week in review: Cisco fixes critical UCCX flaws, November 2025 Patch Tuesday forecast - Help Net Security

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Securing real-time payments without slowing them down In

3 weeks ago

Critical Control Web Panel vulnerability is actively exploited (CVE-2025-48703) - Help Net Security

CISA adds a Control Web Panel vulnerability (CVE-2025-48703) leading to unauthenticated RCE to its Known Exploited Vulnerabilities catalog.

3 weeks ago

U.S. CISA adds Gladinet CentreStack, and CWP Control Web Panel flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Gladinet CentreStack, and CWP Control Web Panel flaws to its Known Exploited Vulnerabilities catalog.

3 weeks ago

References

EPSS Score

68% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 💰

    Used in Ransomware

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • 📰

    First article discovered by GBHackers News

  • Vulnerability Reserved

.
CVE-2025-48703 : Remote Code Execution Vulnerability in Control Web Panel by CWP