Loading
Generated remediation guidance and an executive summary. No account required.
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
Use CWE-78, Control-Webpanel vendor hub and Webpanel product page to widen CVE-2025-48703 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-44877, CVE-2023-42121 and CVE-2021-45467 for nearby disclosures in the same product family.