KEVIntel
9.8
CVSS
Critical

CVE-2022-44877

PUBLISHED

login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via...

Exploited in the wild Remote Low complexity No user interaction
Vendor
CWP (Control Web Panel)
Product
Control Web Panel
Published
Jan 05, 2023
EPSS

Description

login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.

php cisa nuclei_scanner metasploit

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2023-01-17 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
Yes
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jan 17, 2023

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

control_web_panel_login_cmd_exec

metasploit · Created Unknown

Metasploit module for CVE-2022-44877

hotpotcookie/CVE-2022-44877-white-box

github · Created 2023-02-15 15:22:48 UTC · 6 stars

Red Team utilities for setting up CWP CentOS 7 payload & reverse shell (Red Team 9 - CW2023)

Chocapikk/CVE-2022-44877

github · Created 2023-02-11 20:45:08 UTC · 2 stars

Bash Script for Checking Command Injection Vulnerability on CentOS Web Panel [CWP] (CVE-2022-44877)

komomon/CVE-2022-44877-RCE

github · Created 2023-01-06 16:53:51 UTC · 9 stars

CVE-2022-44877 Centos Web Panel 7 Unauthenticated Remote Code Execution

numanturle/CVE-2022-44877

github · Created 2023-01-05 17:29:10 UTC · 103 stars

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit