CentOS Web Panel remote command execution flaw (CVE-2025-48703)
Vulnerability
Summary
Hide ▲
Show ▼
CentOS Web Panel (CWP) is affected by CVE-2025-48703, a critical remote command execution flaw that lets unauthenticated attackers with a valid username run arbitrary shell commands. CISA says the bug is being actively exploited, and the issue affects all versions before 0.9.8.1204.
Related Happenings
CISA KEV listing for Wing FTP CVE-2025-47813
Public Sector Action
First: 17.03.2026 07:23
Last: 17.03.2026 07:23
Sources 1
About this happening:
CISA added **CVE-2025-47813** in **Wing FTP Server** to the **KEV catalog** after evidence of **active exploitation**, putting the flaw under formal government tracking. The listi...
CISA KEV listing for Wing FTP CVE-2025-47813
Public Sector ActionAbout this happening: CISA added **CVE-2025-47813** in **Wing FTP Server** to the **KEV catalog** after evidence of **active exploitation**, putting the flaw under formal government tracking. The listi...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector Action
First: 04.02.2026 07:50
Last: 04.02.2026 07:50
Sources 1
About this happening:
**CISA** added **CVE-2025-40551** in **SolarWinds Web Help Desk** to the **KEV catalog** and imposed **federal remediation deadlines**, turning a newly exploited flaw into a compl...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector ActionAbout this happening: **CISA** added **CVE-2025-40551** in **SolarWinds Web Help Desk** to the **KEV catalog** and imposed **federal remediation deadlines**, turning a newly exploited flaw into a compl...
CISA adds WatchGuard Fireware CVE-2025-9242 to KEV catalog
Public Sector Action
First: 13.11.2025 09:23
Last: 13.11.2025 09:23
Sources 1
About this happening:
CISA **added** **CVE-2025-9242** in **WatchGuard Fireware** to the **KEV catalog**, signaling **active exploitation** and forcing remediation prioritization. The flaw is an **out-...
CISA adds WatchGuard Fireware CVE-2025-9242 to KEV catalog
Public Sector ActionAbout this happening: CISA **added** **CVE-2025-9242** in **WatchGuard Fireware** to the **KEV catalog**, signaling **active exploitation** and forcing remediation prioritization. The flaw is an **out-...
Gladinet Triofox actively exploited improper access control flaw (CVE-2025-12480)
Vulnerability
First: 11.11.2025 14:30
Last: 11.11.2025 14:30
Sources 1
About this happening:
**Gladinet Triofox** is affected by **CVE-2025-12480**, a **critical improper access control flaw** that let attackers reach restricted setup pages and turn the issue into **code...
Gladinet Triofox actively exploited improper access control flaw (CVE-2025-12480)
VulnerabilityAbout this happening: **Gladinet Triofox** is affected by **CVE-2025-12480**, a **critical improper access control flaw** that let attackers reach restricted setup pages and turn the issue into **code...
CISA KEV remediation deadline for CWP exploit
Public Sector Action
First: 05.11.2025 20:26
Last: 05.11.2025 20:26
Sources 1
How related:
The agency has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and is giving federal entities subject to the BOD 22-01 guidance until November 25 to apply available security updates and vendor-provided mitigations, or stop using the product.
About this happening:
CISA added **CVE-2025-48703** to the **KEV catalog** and set **November 25** as the remediation deadline for federal entities using **CentOS Web Panel (CWP)**. Agencies covered by...
CISA KEV remediation deadline for CWP exploit
Public Sector ActionHow related: The agency has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and is giving federal entities subject to the BOD 22-01 guidance until November 25 to apply available security updates and vendor-provided mitigations, or stop using the product.
About this happening: CISA added **CVE-2025-48703** to the **KEV catalog** and set **November 25** as the remediation deadline for federal entities using **CentOS Web Panel (CWP)**. Agencies covered by...
Timeline
-
05.11.2025 20:26 2 articles · 6mo ago
CentOS Web Panel remote command execution flaw (CVE-2025-48703)
Initial Disclosure**CVE-2025-48703** surfaced as a high-severity CWP command-execution flaw affecting versions before **0.9.8.1204**. The issue was later placed in **CISA’s KEV catalog** after exploitation activity was identified.
Show sources
- CISA warns of critical CentOS Web Panel bug exploited in attacks — www.bleepingcomputer.com — 05.11.2025 20:26
- CISA warns of critical CentOS Web Panel bug exploited in attacks — www.bleepingcomputer.com — 05.11.2025 20:26