
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-48703 is an OS command injection vulnerability in CWP (Control Web Panel, formerly CentOS Web Panel) that allows unauthenticated remote code execution via shell metacharacters injected into the t_total parameter of a filemanager changePerm request. The vulnerability affects all CWP versions before 0.9.8.1205. It was published on September 19, 2025, and added to the CISA Known Exploited Vulnerabilities (KEV) catalog on November 4, 2025. It carries a CVSS v3.1 base score of 9.0 (Critical) (CISA KEV, Red Hat Advisory).
The root cause is improper neutralization of special elements used in OS commands (CWE-78), where user-supplied input in the t_total parameter of the filemanager changePerm API endpoint is passed unsanitized to a shell command. An unauthenticated attacker can inject shell metacharacters (e.g., semicolons, backticks, pipes) to execute arbitrary OS commands on the server. The only precondition is knowledge of a valid non-root username on the target system, which can often be enumerated through other means. A detailed technical write-up and proof-of-concept exploit are publicly available (Fenrisk PoC, GitHub PoC).
Successful exploitation grants an unauthenticated attacker arbitrary OS command execution on the affected server, enabling complete system compromise including data theft, unauthorized file modification, service disruption, and potential lateral movement within the hosting environment. Because CWP is a web hosting control panel typically managing multiple hosted websites and accounts, a compromise can expose all hosted customer data and configurations. The vulnerability has been observed in ransomware-adjacent campaigns and was also leveraged by the PCPJack cloud worm for credential theft at scale across cloud infrastructure (CISA KEV, SentinelOne PCPJack).
This vulnerability is actively exploited in the wild and was added to the CISA KEV catalog on November 4, 2025, with a remediation due date of November 25, 2025 (CISA KEV). Multiple public PoC exploits exist, including write-ups on Fenrisk and several GitHub repositories (Fenrisk PoC, GitHub PoC 1, GitHub PoC 2). The threat actor group TeamPCP and the PCPJack cloud worm have been attributed to exploitation of this CVE as part of multi-CVE campaigns targeting cloud systems (SentinelOne PCPJack, The Hacker News). The EPSS score is 0.00158, though real-world exploitation activity significantly exceeds what this score suggests. Nuclei detection templates have also been published for automated scanning (ProjectDiscovery).
changePerm endpoint (e.g., /filemanager2/api/changePerm) on the CWP administrative interface.t_total parameter, such as t_total=755;id; or using backtick/pipe syntax to chain arbitrary commands alongside the legitimate permission value.t_total value in a shell command, executing the injected payload as the web server or CWP process user, returning command output or establishing a reverse shell./filemanager2/api/changePerm or similar CWP filemanager endpoints containing shell metacharacters (;, |, `, $()) in the t_total parameter; unexpected outbound connections from the CWP server to external IPs on non-standard ports./tmp; presence of web shells, reverse shell scripts, or credential harvesting tools; unauthorized SSH authorized_keys modifications.bash, sh, curl, wget, python, perl); processes performing network scanning or lateral movement from the CWP host.The vendor has released a patch in CWP version 0.9.8.1205; all users should upgrade immediately (CISA KEV). CISA's BOD 22-01 guidance applies for federal agencies, with a due date of November 25, 2025. If immediate patching is not possible, restrict network access to CWP administrative interfaces (ports 2030, 2031, 2086) to trusted IP ranges only, and implement network-based intrusion detection signatures to detect exploitation attempts targeting the changePerm endpoint with shell metacharacters in the t_total parameter. Monitor for suspicious process activity originating from the CWP service account.
CISA added CVE-2025-48703 to its KEV catalog on November 4, 2025, and issued an alert highlighting active exploitation (CISA Alert). SecurityWeek, BleepingComputer, The Hacker News, and Help Net Security all covered the active exploitation and CISA KEV addition (BleepingComputer, The Hacker News). The Center for Internet Security (CIS) issued an advisory noting the potential for remote code execution (CIS Advisory). Check Point Research included the vulnerability in its November 10, 2025 threat intelligence report, and SentinelOne later documented its use by the PCPJack cloud worm in May 2026 (Check Point, SentinelOne PCPJack). Community discussion was active on Reddit r/netsec and r/blueteamsec, with multiple Mastodon and Bluesky posts amplifying the CISA KEV addition.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."