
⚠️ **Vulnerability Alert:** CentOS Web Panel (CWP) Remote Code Execution (RCE) - CVE-2025-48703 🆔 **CVE-2025-48703** | 📊 CVSS: 9.0 (CRITICAL 🔴) | 📈 EPSS: 98.336% 🛠️ **Exploit Maturity:** Proof-of-Concept 📂 **Affected Versions:** < 0.9.8.1205 🔧 **Fixed Versions:** 0.9.8.1205 🫨 **Attack Vectors:** - Network (remote, unauthenticated) - Command injection via 't_total' parameter in filemanager changePerm request - Requires knowledge of a valid non-root username - High attack complexity (AV:N/AC:H) 📝 **Summary:** Unauthenticated attackers can achieve remote code execution in CWP via the t_total parameter, allowing hijack of non-root accounts and potential full server compromise. Public PoC increases the risk of active exploitation — patch immediately. 📈 **Impact Scope:** Unauthenticated RCE enabling hijack of non-root accounts, lateral movement, persistence, and potential full server compromise on affected CWP hosts. Public PoC increases exploitation risk. 🛡️ **Recommended Actions:** - Apply vendor update to 0.9.8.1205 or later immediately - Restrict network access to CWP interfaces and implement firewall/ACLs 🪢 **Related Resources:** - https://control-webpanel.com/changelog - https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48703 🏷 **Tags:** #Cybersecurity #CWP #RCE
Post summary
The alert announces a critical RCE (CVE-2025-48703) in CentOS Web Panel, provides technical details and a public PoC, and urges users to immediately apply the vendor patch to version 0.9.8.1205 or later.

