CVE-2022-25047
Control Web Panel vulnerability analysis and mitigation

Overview

The vulnerability (CVE-2022-25047) affects Control Web Panel (CWP) v0.9.8.1126, where the password reset token is generated using known or predictable values. This vulnerability was discovered and responsibly disclosed by Immersive Labs researchers in early 2022. CWP is a shared hosting platform built to run on CentOS servers, with approximately 185,000 active servers potentially impacting millions of websites (Immersive Labs Blog).

Technical details

The vulnerability exists in the password reset functionality where the token generation process uses predictable elements. The reset token can be calculated if an attacker knows the email address and username of any given user. When a password reset is triggered, the server response contains the date and time of the request, which matches the date used to generate the reset token (Immersive Labs Blog).

Impact

This vulnerability allows attackers to take over user accounts by bypassing the password reset process without requiring access to the target's email account. With hundreds of thousands of active CWP servers online, each hosting between 10 and 100 websites, millions of websites could potentially be affected. Attackers could use compromised accounts to inject credential harvesting malware or target payment portals (Immersive Labs Blog).

Mitigation and workarounds

The vulnerability has been patched by the CWP team. CWP implements an automatic update process that includes forced expiry of instances that aren't kept up to date. All vulnerable versions have now passed their forced expiry date. Users should ensure their CWP installations are updated to the latest version (Immersive Labs Blog).

Additional resources


SourceThis report was generated using AI

Related Control Web Panel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-42121CRITICAL9.8
  • Control Web PanelControl Web Panel
  • cpe:2.3:a:control-webpanel:webpanel
NoYesMay 03, 2024
CVE-2025-48703CRITICAL9
  • Control Web PanelControl Web Panel
  • cpe:2.3:a:control-webpanel:webpanel
YesYesSep 19, 2025
CVE-2023-42123HIGH8.8
  • Control Web PanelControl Web Panel
  • cpe:2.3:a:control-webpanel:webpanel
NoYesMay 03, 2024
CVE-2023-42120HIGH8.8
  • Control Web PanelControl Web Panel
  • cpe:2.3:a:control-webpanel:webpanel
NoYesMay 03, 2024
CVE-2023-42122HIGH7.8
  • Control Web PanelControl Web Panel
  • cpe:2.3:a:control-webpanel:webpanel
NoYesMay 03, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management