CyberSec.Space Logo
CVEブラウザに戻る

CVE-2025-48703

🔥 Known Exploited (CISA KEV)CRITICAL
9.0
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-09-19
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

Affected Platforms (CPE)

📦
Control Webpanel

Webpanel

< 0.9.8.1205

References & Advisories

関連する脆弱性情報