CWP Control Web Panel OS Command Injection Vulnerability
Due Soon
CWP / Control Web Panel
CWE-78
Description
CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Additional Information
- Catalog Version
- 2025.11.21
- Catalog Released
- Nov. 21, 2025
- Days Until Due
- 2 days
- Last Updated
- 1 day, 9 hours ago