← Browse

CVE-2025-48703

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
99.7%
100.0th percentile
CISA KEV
Listed
Added 2025-11-04 · patch by 2025-11-25
Weakness / dates
Published — · modified —

Description

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

Official: NVD · CVE.org