CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
Is CVE-2025-48703 exploited?
Listed in the CISA KEV catalog on 2025-11-04.
Federal remediation due 2025-11-25.
Past that date by 263 days.
EPSS puts exploitation in the next 30 days at 99.6%.
Public exploit code: none found in monitored sources.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2025-48703
PlainSec has not published a story about this CVE.