CVE-2022-44877
KEVCRITICAL 9.8EPSS 100.0%
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2023-01-17
- Nuclei
- critical · CWE-78
- Published
- 2023-01-05
- Updated
- 2025-10-21
Proof-of-concept exploits (14)
- http://packetstormsecurity.com/files/170388/Control-Web-Panel-7-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/170820/Control-Web-Panel-Unauthenticated-Remote-Comm…
- http://packetstormsecurity.com/files/171725/Control-Web-Panel-7-CWP7-0.9.8.1147-Remote-Co…
- http://seclists.org/fulldisclosure/2023/Jan/1
- https://gist.github.com/numanturle/c1e82c47f4cba24cff214e904c227386
- https://www.youtube.com/watch?v=kiLfSvc1SYY
- Chocapikk/CVE-2022-448774★ · 2023-02-11
- ColdFusionX/CVE-2022-44877-CWP71★ · 2023-02-02
- G01d3nW01f/CVE-2022-448770★ · 2024-02-28
- dkstar11q/CVE-2022-448770★ · 2023-02-11
- hotpotcookie/CVE-2022-44877-white-box6★ · 2023-09-06
- komomon/CVE-2022-44877-RCE10★ · 2023-01-06
- numanturle/CVE-2022-44877103★ · 2023-01-05
- rhymsc/CVE-2022-44877-RCE0★ · 2023-11-18