Threat Advisory

Hackers exploit Control Web Panel flaw to open reverse shells

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

Recently researchers have released a patch for a serious vulnerability in Control Web Panel (CWP), a server management tool formerly known as CentOS Web Panel which is being actively exploited by hackers. The vulnerability tracked as CVE-2022-44877, allows an attacker to execute code remotely without authentication. Attackers are exploiting this flaw to get remote access to unpatched systems.[/subscribe_to_unlock_form]

Summary:

Recently researchers have released a patch for a serious vulnerability in Control Web Panel (CWP), a server management tool formerly known as CentOS Web Panel which is being actively exploited by hackers. The vulnerability tracked as CVE-2022-44877, allows an attacker to execute code remotely without authentication. Attackers are exploiting this flaw to get remote access to unpatched systems.[emaillocker id="1283"]

Recommendation:

We strongly recommend update to the latest version CWP 0.9.8.1148

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/security/hackers-exploit-control-web-panel-flaw-to-open-reverse-shells/

[/emaillocker]
crossmenu