Vulnerability record · CVE-2019-15107 · published 16 August 2019
CVE-2019-15107: Webmin password_change.cgi command injection
Webmin · Webmin
Webmin through 1.920 passes the 'old' parameter in password_change.cgi into a shell command without sanitization, allowing OS command injection. The flaw is remotely reachable and, per the CVSS vector, needs no authentication or user interaction, so any exposed Webmin instance is at risk. It is a critical, actively exploited issue with a near-certain exploitation likelihood score.
Description
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution with a 9.8 CVSS score, KEV listing, ransomware use, and near-maximum EPSS probability makes this an urgent patch-or-isolate case.
What it is
Webmin through 1.920 passes the 'old' parameter in password_change.cgi into a shell command without sanitization, allowing OS command injection. The flaw is remotely reachable and, per the CVSS vector, needs no authentication or user interaction, so any exposed Webmin instance is at risk. It is a critical, actively exploited issue with a near-certain exploitation likelihood score.
Impact
An attacker can execute arbitrary operating system commands on the Webmin host, typically as the Webmin service account, leading to full server compromise. CISA KEV notes known ransomware campaign use, so impact extends to data theft and destructive encryption.
Attack surface
Reached over the network via HTTP requests to password_change.cgi on the Webmin web interface. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Listed in CISA KEV since 2022-03-25 with known ransomware use, and EPSS 30-day probability is 0.99766 (99.955th percentile). Multiple public exploit references (ExploitDB 47230, Packet Storm, DEFCON material) confirm weaponized code is available.
What to do
- Upgrade Webmin to a version later than 1.920 per the vendor security advisory.
- Restrict network access to the Webmin interface (default port 10000) to trusted management hosts only.
- If Webmin is not required, disable or uninstall it.
- Audit for unauthorized changes or persistence on hosts that ran vulnerable Webmin versions.
- Monitor vendor advisories for any follow-up fixes affecting the password_change.cgi path.
Detection
- Inspect Webmin HTTP logs for POST requests to password_change.cgi, especially with unusual 'old' parameter values containing shell metacharacters.
- Alert on child processes spawned by the Webmin service (e.g., shell, curl, wget, nc) outside normal admin activity.
- Hunt for outbound connections or file writes originating from the Webmin process user.
- Correlate Webmin access logs with endpoint process creation telemetry around the same timestamp.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-15107 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Webmin Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-15107 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-15107), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.