CVE-2025-48703Patch(control-webpanel / webpanel)

HIGHCVSS 9.0 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch control-webpanel webpanel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-11-25. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webpanel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-04-06); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
webpanel

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-06: 1Mentions · 2026-05-08: 1PoC Mentioned / Linked · 2026-04-06: 1Exploit Tool / Code · 2026-05-08: 1Active Exploitation · 2026-05-08: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-04-06: 1Technical Details · 2026-05-08: 104-0605-08
Signal classification2 categories
Patch
150.0%
Exploit
150.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-061
Patch1
2026-05-081
Exploit1
Full discourse2 posts
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** CentOS Web Panel (CWP) Remote Code Execution (RCE) - CVE-2025-48703 🆔 **CVE-2025-48703** | 📊 CVSS: 9.0 (CRITICAL 🔴) | 📈 EPSS: 98.336% 🛠️ **Exploit Maturity:** Proof-of-Concept 📂 **Affected Versions:** < 0.9.8.1205 🔧 **Fixed Versions:** 0.9.8.1205 🫨 **Attack Vectors:** - Network (remote, unauthenticated) - Command injection via 't_total' parameter in filemanager changePerm request - Requires knowledge of a valid non-root username - High attack complexity (AV:N/AC:H) 📝 **Summary:** Unauthenticated attackers can achieve remote code execution in CWP via the t_total parameter, allowing hijack of non-root accounts and potential full server compromise. Public PoC increases the risk of active exploitation — patch immediately. 📈 **Impact Scope:** Unauthenticated RCE enabling hijack of non-root accounts, lateral movement, persistence, and potential full server compromise on affected CWP hosts. Public PoC increases exploitation risk. 🛡️ **Recommended Actions:** - Apply vendor update to 0.9.8.1205 or later immediately - Restrict network access to CWP interfaces and implement firewall/ACLs 🪢 **Related Resources:** - https://control-webpanel.com/changelog - https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48703 🏷 **Tags:** #Cybersecurity #CWP #RCE

    Post summary

    The alert announces a critical RCE (CVE-2025-48703) in CentOS Web Panel, provides technical details and a public PoC, and urges users to immediately apply the vendor patch to version 0.9.8.1205 or later.

    01000161
    273 followersView on X
  • SecureChap@SecureChap
    Exploit

    "PCP replaced" - the metric tracked by PCPJack's C2. PCPJack is a Linux credential-stealing worm disclosed May 7, 2026 by SentinelLabs. It exploits five CVEs to spread: - CVE-2025-29927 (Next.js middleware auth bypass) - CVE-2025-55182 "React2Shell" (Next.js Server Actions deserialization) - CVE-2026-1357 (WPVivid Backup unauth file upload) - CVE-2025-9501 (W3 Total Cache PHP injection via cached mfunc) - CVE-2025-48703 (CentOS Web Panel Filemanager shell injection) http://bootstrap.sh kills competing TeamPCP processes before installing itself, then drops six Python scripts handling orchestration, credential parsing, lateral movement, encryption, cloud-IP refresh, and port scanning. Lateral movement targets SSH, Kubernetes, Docker, Redis, RayML, MongoDB. Persistence via systemd, cron, Redis rewrites, and privileged containers. Targets pulled from Common Crawl parquet files. http://check.sh probes IMDS endpoints and Kubernetes service accounts. Credentials harvested cover Anthropic, OpenAI, HashiCorp Vault, 1Password, Slack, SSH keys, and WordPress configs. Exfil uses X25519 ECDH + ChaCha20-Poly1305, 2800-byte chunks, to Telegram. SentinelLabs links it to a likely former TeamPCP affiliate from tooling overlap. No cryptomining, unlike TeamPCP - the C2 explicitly tracks "PCP replaced" successes. A worm built to evict its predecessor and harvest the cloud underneath.

    Post summary

    The post describes PCPJack, a Linux credential‑stealing worm that actively exploits five CVEs using built‑in scripts, demonstrating real‑world misuse of those vulnerabilities.

    000001.3K
    153 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcontrol-webpanelwebpanel---

Explore more