CVE-2025-48703
Control Web Panel vulnerability analysis and mitigation

Overview

CVE-2025-48703 is an OS command injection vulnerability in CWP (Control Web Panel, formerly CentOS Web Panel) that allows unauthenticated remote code execution via shell metacharacters injected into the t_total parameter of a filemanager changePerm request. The vulnerability affects all CWP versions before 0.9.8.1205. It was published on September 19, 2025, and added to the CISA Known Exploited Vulnerabilities (KEV) catalog on November 4, 2025. It carries a CVSS v3.1 base score of 9.0 (Critical) (CISA KEV, Red Hat Advisory).

Technical details

The root cause is improper neutralization of special elements used in OS commands (CWE-78), where user-supplied input in the t_total parameter of the filemanager changePerm API endpoint is passed unsanitized to a shell command. An unauthenticated attacker can inject shell metacharacters (e.g., semicolons, backticks, pipes) to execute arbitrary OS commands on the server. The only precondition is knowledge of a valid non-root username on the target system, which can often be enumerated through other means. A detailed technical write-up and proof-of-concept exploit are publicly available (Fenrisk PoC, GitHub PoC).

Impact

Successful exploitation grants an unauthenticated attacker arbitrary OS command execution on the affected server, enabling complete system compromise including data theft, unauthorized file modification, service disruption, and potential lateral movement within the hosting environment. Because CWP is a web hosting control panel typically managing multiple hosted websites and accounts, a compromise can expose all hosted customer data and configurations. The vulnerability has been observed in ransomware-adjacent campaigns and was also leveraged by the PCPJack cloud worm for credential theft at scale across cloud infrastructure (CISA KEV, SentinelOne PCPJack).

Exploitability

This vulnerability is actively exploited in the wild and was added to the CISA KEV catalog on November 4, 2025, with a remediation due date of November 25, 2025 (CISA KEV). Multiple public PoC exploits exist, including write-ups on Fenrisk and several GitHub repositories (Fenrisk PoC, GitHub PoC 1, GitHub PoC 2). The threat actor group TeamPCP and the PCPJack cloud worm have been attributed to exploitation of this CVE as part of multi-CVE campaigns targeting cloud systems (SentinelOne PCPJack, The Hacker News). The EPSS score is 0.00158, though real-world exploitation activity significantly exceeds what this score suggests. Nuclei detection templates have also been published for automated scanning (ProjectDiscovery).

Exploitation steps

  1. Reconnaissance: Identify internet-facing CWP instances using Shodan, Censys, or similar tools by searching for CWP login pages or default ports (e.g., 2030, 2031, 2086). Enumerate valid non-root usernames via CWP's public-facing login error messages, hosting provider leaks, or other OSINT methods.
  2. Craft malicious request: Construct an HTTP POST request targeting the filemanager changePerm endpoint (e.g., /filemanager2/api/changePerm) on the CWP administrative interface.
  3. Inject shell metacharacters: Insert OS command injection payload into the t_total parameter, such as t_total=755;id; or using backtick/pipe syntax to chain arbitrary commands alongside the legitimate permission value.
  4. Achieve code execution: The server processes the unsanitized t_total value in a shell command, executing the injected payload as the web server or CWP process user, returning command output or establishing a reverse shell.
  5. Post-exploitation: Use the initial foothold to escalate privileges, harvest credentials stored in CWP configuration files, deploy persistent backdoors, or pivot to other hosted accounts and cloud infrastructure (Fenrisk PoC, CISA KEV).

Indicators of compromise

  • Network: Unusual HTTP POST requests to /filemanager2/api/changePerm or similar CWP filemanager endpoints containing shell metacharacters (;, |, `, $()) in the t_total parameter; unexpected outbound connections from the CWP server to external IPs on non-standard ports.
  • Logs: CWP access logs showing POST requests to filemanager changePerm endpoints from unknown or foreign IP addresses; web server error logs showing shell command output fragments; authentication logs showing access with valid non-root usernames from unexpected sources.
  • File System: New or modified files in CWP web directories or /tmp; presence of web shells, reverse shell scripts, or credential harvesting tools; unauthorized SSH authorized_keys modifications.
  • Process: Unexpected child processes spawned by the CWP web server process (e.g., bash, sh, curl, wget, python, perl); processes performing network scanning or lateral movement from the CWP host.
  • Threat Actor Artifacts: Presence of PCPJack worm components or TeamPCP tooling; evidence of credential harvesting from Docker, Kubernetes, Redis, or MongoDB configurations (SentinelOne PCPJack, CISA KEV).

Mitigation and workarounds

The vendor has released a patch in CWP version 0.9.8.1205; all users should upgrade immediately (CISA KEV). CISA's BOD 22-01 guidance applies for federal agencies, with a due date of November 25, 2025. If immediate patching is not possible, restrict network access to CWP administrative interfaces (ports 2030, 2031, 2086) to trusted IP ranges only, and implement network-based intrusion detection signatures to detect exploitation attempts targeting the changePerm endpoint with shell metacharacters in the t_total parameter. Monitor for suspicious process activity originating from the CWP service account.

Community reactions

CISA added CVE-2025-48703 to its KEV catalog on November 4, 2025, and issued an alert highlighting active exploitation (CISA Alert). SecurityWeek, BleepingComputer, The Hacker News, and Help Net Security all covered the active exploitation and CISA KEV addition (BleepingComputer, The Hacker News). The Center for Internet Security (CIS) issued an advisory noting the potential for remote code execution (CIS Advisory). Check Point Research included the vulnerability in its November 10, 2025 threat intelligence report, and SentinelOne later documented its use by the PCPJack cloud worm in May 2026 (Check Point, SentinelOne PCPJack). Community discussion was active on Reddit r/netsec and r/blueteamsec, with multiple Mastodon and Bluesky posts amplifying the CISA KEV addition.

Additional resources


SourceThis report was generated using AI

Related Control Web Panel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-42121CRITICAL9.8
  • Control Web Panel logoControl Web Panel
  • cpe:2.3:a:control-webpanel:webpanel
NoYesMay 03, 2024
CVE-2026-57517CRITICAL9.3
  • Control Web Panel logoControl Web Panel
  • cpe:2.3:a:control-webpanel:webpanel
NoYesJul 01, 2026
CVE-2025-48703CRITICAL9
  • Control Web Panel logoControl Web Panel
  • cpe:2.3:a:control-webpanel:webpanel
YesYesSep 19, 2025
CVE-2023-42123HIGH8.8
  • Control Web Panel logoControl Web Panel
  • cpe:2.3:a:control-webpanel:webpanel
NoYesMay 03, 2024
CVE-2023-42122HIGH7.8
  • Control Web Panel logoControl Web Panel
  • cpe:2.3:a:control-webpanel:webpanel
NoYesMay 03, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management