CVE-2025-48703 - CVE House
Back to Database
Status published Critical CVE-2025-48703

CWP (aka Control Web Panel or CentOS Web Panel) before...

Vulnerability Description

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-48703

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

centos-webpanel

View all reports →

Affected Software

CentOS Web Panel
Vulnerable Versions:
0

Timeline

Official Publish: September 19th, 2025
Last Modified: February 26th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)