CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Critical Remote Command Execution Vulnerability Exploited in CentOS Web Panel

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A critical remote command execution vulnerability (CVE-2025-48703) in CentOS Web Panel (CWP) is being actively exploited. The flaw allows unauthenticated attackers to execute arbitrary shell commands as a valid user. The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, urging federal entities to patch or discontinue use by November 25. The issue affects all CWP versions before 0.9.8.1204. The vulnerability was demonstrated in late June and reported to CWP on May 13. The fix was released on June 18 in version 0.9.8.1205. CISA did not provide details on the exploitation methods, targets, or origin of the malicious activity.

Timeline

  1. 05.11.2025 20:26 1 articles · 5d ago

    CISA warns of actively exploited critical CentOS Web Panel bug

    CISA added the critical remote command execution vulnerability (CVE-2025-48703) in CentOS Web Panel (CWP) to its Known Exploited Vulnerabilities (KEV) catalog. The flaw allows unauthenticated attackers to execute arbitrary shell commands as a valid user. Federal entities are urged to patch or discontinue use by November 25. The issue affects all CWP versions before 0.9.8.1204. The vulnerability was demonstrated in late June and reported to CWP on May 13. The fix was released on June 18 in version 0.9.8.1205.

    Show sources

Information Snippets