Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

CISA Warns of CWP Vulnerability Exploited in the Wild

A critical vulnerability in Control Web Panel (CWP), tracked as CVE-2025-48703, allows remote, unauthenticated command execution.

CISA KEV

The cybersecurity agency CISA on Tuesday warned that a critical vulnerability affecting the Control Web Panel (CWP) server administration software has been exploited in the wild.

CWP, previously named CentOS Web Panel, is a free and widely used Linux web hosting control panel that is designed to simplify server management.

A vulnerability in CWP, tracked as CVE-2025-48703, allows remote, unauthenticated attackers to execute arbitrary commands on vulnerable systems. An attacker in possession of a valid non-root username can bypass authentication and execute commands using specially crafted requests. 

The vulnerability was reported to CWP developers in mid-May and patched roughly one month later with the release of version 0.9.8.1205.

There do not appear to be any public reports describing attacks in which CVE-2025-48703 has been exploited. 

Findsec warned a few months ago that exploitation of the vulnerability had been imminent. The company noted that exploitation could be automated and that threat actors had already started developing and sharing exploits on cybercrime forums.

Advertisement. Scroll to continue reading.

According to Netlas.io, there are roughly 150,000 internet-exposed CWP instances that are potentially affected by CVE-2025-48703, a majority in the United States (37,510), followed by Germany, Japan, India, France, and Canada. Shodan shows more than 220,000 internet-exposed instances. 

Given this widespread exposure, it’s highly likely that the vulnerability has been exploited in opportunistic attacks. 

CISA added CVE-2025-48703 to its Known Exploited Vulnerabilities (KEV) catalog and instructed federal agencies to address it by November 25. 

In-the-wild exploitation of a CWP vulnerability was previously reported in early 2023. 

Related: Critical Flaw in Popular React Native NPM Package Exposes Developers to Attacks

Related: CISA Warns of Exploited DELMIA Factory Software Vulnerabilities

Related: CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.