CVE-2025-67888Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized before being used to execute OS commands. This can be exploited by unauthenticated attackers to inject and execute arbitrary OS commands with the privileges of root on the web server. Softaculous or SitePad must be present.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-10); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-10: 1Mentions · 2026-05-26: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-26: 105-1005-26
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-101
Disclosure1
2026-05-261
Patch1
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-67888 An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is s… https://www.cve.org/CVERecord?id=CVE-2025-67888

    Post summary

    The text announces a newly discovered vulnerability (CVE-2025-67888) in Control Web Panel (pre‑0.9.8.1209), describing the input mechanism but providing no exploit code, patch, or evidence of live attacks.

    00020846
    57.8K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2025-67888 (CVSS 7.3) Control Web Panel <0.9.8.1209 vulnerable to unauthenticated RCE via command injection. Attackers can execute arbitrary OS commands as root. Patch immediately if running CWP with Softaculous/SitePad. #CVE #PatchNow https://t.co/VHttQu2ZvQ

    Post summary

    The tweet announces a high‑severity RCE vulnerability in Control Web Panel and urges users to apply the patch immediately.

    00000184
    30 followersView on X

Explore more