CVE-2022-44877
CRITICAL KEV NUCLEICWP login.php Unauthenticated RCE
Title source: metasploitDescription
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
Exploits (13)
nomisec
WORKING POC
6 stars
by hotpotcookie · poc
https://github.com/hotpotcookie/CVE-2022-44877-white-box
metasploit
WORKING POC
EXCELLENT
by Spencer McIntyre, Numan Türle · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/control_web_panel_login_cmd_exec.rb
Nuclei Templates (1)
CentOS Web Panel 7 <0.9.8.1147 - Remote Code Execution
CRITICALVERIFIEDby For3stCo1d
Shodan:
http.title:"Login | Control WebPanel" || http.title:"login | control webpanel"
FOFA:
title="login | control webpanel"
References (7)
Scores
CVSS v3
9.8
EPSS
0.9446
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2023-01-17
VulnCheck KEV
2023-01-11
InTheWild.io
2023-01-12
ENISA EUVD
EUVD-2022-47807
Classification
CWE
CWE-78
Status
published
Affected Products (1)
control-webpanel/webpanel
< 0.9.8.1147
Timeline
Published
Jan 05, 2023
KEV Added
Jan 17, 2023
Tracked Since
Feb 18, 2026