CVE-2022-44877
control-webpanel webpanel
Published 5 Jan 2023 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 17 Jan 2023, with a remediation deadline of 7 Feb 2023 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
References
- packetstormsecurity.com/files/170388/Control-Web-Panel-7-Remote-Code-Execution.html · Exploit, Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/170820/Control-Web-Panel-Unauthenticated-Remote-Command-Execution.html · Exploit, Third Party Advisory, VDB Entry
- packetstormsecurity.com/files/171725/Control-Web-Panel-7-CWP7-0.9.8.1147-Remote-Code-Execution.html · Exploit, Third Party Advisory, VDB Entry
- seclists.org/fulldisclosure/2023/Jan/1 · Exploit, Mailing List, Third Party Advisory
- gist.github.com/numanturle/c1e82c47f4cba24cff214e904c227386 · Exploit, Third Party Advisory
- www.youtube.com/watch?v=kiLfSvc1SYY · Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-44877 · US Government Resource