CWP Control Web Panel OS Command Injection Vulnerability
Summary
| CVE | CVE-2022-44877 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-05 23:15:00 UTC |
| Updated | 2023-04-06 17:15:00 UTC |
| Description | login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter. |
Risk And Classification
EPSS: 0.999950000 probability, percentile 0.999870000 (date 2026-07-22)
CISA KEV: Listed on 2023-01-17; due 2023-02-07; ransomware use Unknown
Problem Types: CWE-78
CISA Known Exploited Vulnerability
| Vendor | CWP |
|---|---|
| Product | Control Web Panel |
| Name | CWP Control Web Panel OS Command Injection Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://control-webpanel.com/changelog#1669855527714-450fb335-6194; https://nvd.nist.gov/vuln/detail/CVE-2022-44877 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Centos-webpanel | Centos Web Panel | All | All | All | All |
| Application | Control-webpanel | Webpanel | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| # Centos Web Panel 7 Unauthenticated Remote Code Execution - CVE-2022-44877 · GitHub | MISC | gist.github.com | |
| Control Web Panel Unauthenticated Remote Command Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Please update your browser | MISC | www.youtube.com | |
| Full Disclosure: Centos Web Panel 7 Unauthenticated Remote Code Execution - CVE-2022-44877 | FULLDISC | seclists.org | |
| Control Web Panel 7 (CWP7) 0.9.8.1147 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Control Web Panel 7 Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150642 Control Web Panel 7 (CWP7) Unauthenticated Remote Code Execution (RCE) Vulnerability (CVE-2022-44877)
- 377965 CWP7 (Control Web Panel 7 or CentOS Web Panel 7) Remote Code Execution (RCE) Vulnerability
- 730694 CWP7 (Control Web Panel 7 or CentOS Web Panel 7) Remote Code Execution (RCE) Vulnerability