CVE-2022-0824

HIGH NUCLEI LAB

webmin < 1.990 - Improper Access Control to Remote Code Execution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 7 public exploits for CVE-2022-0824. PoCs published by faisalfs10x, honypot, pizza-power, including Metasploit module exploits/linux/http/webmin_file_manager_rce. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit leverages an authenticated RCE vulnerability in Webmin <= 1.984 by uploading a malicious Perl reverse shell script via the file manager extension and executing it. It requires valid credentials and a listener setup for the reverse shell.

Description

Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

Exploits (7)

exploitdb WORKING POC
by faisalfs10x · pythonwebappslinux
https://www.exploit-db.com/exploits/50809

This exploit leverages an authenticated RCE vulnerability in Webmin <= 1.984 by uploading a malicious Perl reverse shell script via the file manager extension and executing it. It requires valid credentials and a listener setup for the reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Webmin <= 1.984
Auth required
Prerequisites: Valid Webmin credentials · Network access to target · Listener setup for reverse shell
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 111 stars
by faisalfs10x · poc
https://github.com/faisalfs10x/Webmin-CVE-2022-0824-revshell

This is a functional exploit for CVE-2022-0824, targeting Webmin's File Manager privilege escalation vulnerability. It leverages improper access control to download and execute a reverse shell payload with root privileges.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Webmin 1.984 and below
Auth required
Prerequisites: Valid Webmin credentials · Network access to target · Attacker-controlled HTTP server for payload hosting
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 4 stars
by honypot · poc
https://github.com/honypot/CVE-2022-0824

This repository provides a Docker-based deployment of Webmin 1.984, which is vulnerable to an authenticated RCE exploit (CVE-2022-0824). The vulnerability allows low-privilege users to execute arbitrary commands via the File Manager module by chaining file download and permission modification functionalities.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Webmin 1.984
Auth required
Prerequisites: Authenticated access to Webmin · File Manager module access (even without explicit permissions)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 3 stars
by pizza-power · poc
https://github.com/pizza-power/golang-webmin-CVE-2022-0824-revshell

This Go-based exploit targets CVE-2022-0824 in Webmin <= 1.984, leveraging a BAC vulnerability to upload a Perl reverse shell payload, modify its permissions, and execute it. It requires valid credentials and a callback listener.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Webmin <= 1.984
Auth required
Prerequisites: Valid Webmin credentials · Network access to target · Callback listener setup
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by NUDTTAN91 · poc
https://github.com/NUDTTAN91/Webmin-CVE-2022-0824-Enhanced-Exploit

This repository contains an enhanced exploit for CVE-2022-0824, a critical arbitrary file upload vulnerability in Webmin. The exploit supports both direct command execution and reverse shell modes, with multiple payload types and intelligent file management.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Webmin < 1.990
Auth required
Prerequisites: Valid Webmin credentials · Network access to Webmin interface · Python 3.6+ environment
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by gokul-ramesh · poc
https://github.com/gokul-ramesh/WebminRCE-exploit

This PoC exploits CVE-2022-0824 in Webmin by leveraging improper access control to upload a malicious CGI file via the File Manager module, then executing it to achieve remote code execution (RCE). The exploit involves authentication, file upload, permission modification, and reverse shell execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Webmin (versions affected by CVE-2022-0824)
Auth required
Prerequisites: Valid credentials for a low-privileged Webmin user · Network access to the target Webmin instance · A listener for the reverse shell
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by faisalfs10x, jheysel-r7 · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/webmin_file_manager_rce.rb

This Metasploit module exploits CVE-2022-0824 in Webmin 1.984 by chaining file download and permission modification functionalities to achieve RCE via a crafted .cgi file. It authenticates as a low-privilege user, downloads a malicious payload, sets executable permissions, and triggers execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Webmin 1.984
Auth required
Prerequisites: Valid Webmin credentials · Network access to Webmin port (default: 10000)
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Nuclei Templates (1)

Webmin <1.990 - Improper Access Control
HIGHby cckuailong
Shodan: http.title:"webmin"
FOFA: title="webmin"

Scores

CVSS v3 8.8
EPSS 0.9698
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284 CWE-863
Status published
Products (1)
webmin/webmin < 1.990
Published Mar 02, 2022
Tracked Since Feb 18, 2026