← Vulnerability feed

Vulnerability record · CVE-2019-15107 · published 16 August 2019

CVE-2019-15107: Webmin password_change.cgi command injection

Webmin · Webmin

Webmin through 1.920 passes the 'old' parameter in password_change.cgi into a shell command without sanitization, allowing OS command injection. The flaw is remotely reachable and, per the CVSS vector, needs no authentication or user interaction, so any exposed Webmin instance is at risk. It is a critical, actively exploited issue with a near-certain exploitation likelihood score.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2022 Known ransomware use EPSS 100% · top 0.1% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 10.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
17References, 10 tagged exploit
6 Aug 2026Last modified by NVD

Description

An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with a 9.8 CVSS score, KEV listing, ransomware use, and near-maximum EPSS probability makes this an urgent patch-or-isolate case.

What it is

Webmin through 1.920 passes the 'old' parameter in password_change.cgi into a shell command without sanitization, allowing OS command injection. The flaw is remotely reachable and, per the CVSS vector, needs no authentication or user interaction, so any exposed Webmin instance is at risk. It is a critical, actively exploited issue with a near-certain exploitation likelihood score.

Impact

An attacker can execute arbitrary operating system commands on the Webmin host, typically as the Webmin service account, leading to full server compromise. CISA KEV notes known ransomware campaign use, so impact extends to data theft and destructive encryption.

Attack surface

Reached over the network via HTTP requests to password_change.cgi on the Webmin web interface. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

Listed in CISA KEV since 2022-03-25 with known ransomware use, and EPSS 30-day probability is 0.99766 (99.955th percentile). Multiple public exploit references (ExploitDB 47230, Packet Storm, DEFCON material) confirm weaponized code is available.

What to do

  • Upgrade Webmin to a version later than 1.920 per the vendor security advisory.
  • Restrict network access to the Webmin interface (default port 10000) to trusted management hosts only.
  • If Webmin is not required, disable or uninstall it.
  • Audit for unauthorized changes or persistence on hosts that ran vulnerable Webmin versions.
  • Monitor vendor advisories for any follow-up fixes affecting the password_change.cgi path.

Detection

  • Inspect Webmin HTTP logs for POST requests to password_change.cgi, especially with unusual 'old' parameter values containing shell metacharacters.
  • Alert on child processes spawned by the Webmin service (e.g., shell, curl, wget, nc) outside normal admin activity.
  • Hunt for outbound connections or file writes originating from the Webmin process user.
  • Correlate Webmin access logs with endpoint process creation telemetry around the same timestamp.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-15107 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Webmin Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/154141/Webmin-1.920-Remote-Command-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154141/Webmin-Remote-Comman-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154197/Webmin-1.920-password_change.cgi-Backdoor.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154485/Webmin-1.920-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://www.pentest.com.tr/exploits/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.html ExploitThird Party Advisory
http://www.webmin.com/security.html Vendor Advisory
https://attackerkb.com/topics/hxx3zmiCkR/webmin-password-change-cgi-command-injection Third Party Advisory
https://www.exploit-db.com/exploits/47230 ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154141/Webmin-1.920-Remote-Command-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154141/Webmin-Remote-Comman-Execution.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154197/Webmin-1.920-password_change.cgi-Backdoor.html ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/154485/Webmin-1.920-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://www.pentest.com.tr/exploits/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.html ExploitThird Party Advisory
http://www.webmin.com/security.html Vendor Advisory
https://attackerkb.com/topics/hxx3zmiCkR/webmin-password-change-cgi-command-injection Third Party Advisory
https://www.exploit-db.com/exploits/47230 ExploitThird Party AdvisoryVDB Entry
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-15107 US Government Resource

Track CVE-2019-15107 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-1177Usermin vulnerabilityUnknown vulnerability in (1) Webmin and (2) Usermin before 1.200 causes Webmin to change permissions and ownership of configuration files, with unkno…EPSS 1.8%10.0CVE-2003-0101Engardelinux guardian digital webtool vulnerabilityminiserv.pl in (1) Webmin before 1.070 and (2) Usermin before 1.000 does not properly handle metacharacters such as line feeds and carriage returns (…EPSS 15%10.0CVE-2002-2201Webmin vulnerabilityThe Printer Administration module for Webmin 0.990 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the …EPSS 3.3%10.0CVE-2001-1196Webmin vulnerabilityDirectory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argumen…EPSS 9.8%9.8CVE-2022-36446Webmin apt-lib.pl command injection via unescaped UI commandWebmin before 1.997 fails to HTML-escape a UI command in software/apt-lib.pl, allowing injection of commands through that interface. The flaw is remo…EPSS 96%analysed9.8CVE-2020-35769Webmin vulnerabilityminiserv.pl in Webmin 1.962 on Windows mishandles special characters in query arguments to the CGI program.EPSS 1.8%9.8CVE-2018-8712Webmin path traversal vulnerabilityAn issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak d…EPSS 1.8%9.6CVE-2021-32157Webmin cross-site scripting vulnerabilityA Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2019-15107), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.