← Vulnerability feed

Vulnerability record · CVE-2021-45466 · published 26 December 2022

CVE-2021-45466: CWP pre-auth request lets attacker plant authorized_keys file

Control Webpanel · Webpanel

Control Web Panel (CWP) before 0.9.8.1107 mishandles authorization on the api/?api=add_server&DHCP= endpoint, allowing a crafted request to write an authorized_keys text file into the /resources/ folder. Because the endpoint is reachable without credentials, this is a pre-auth file-write primitive on a hosting control panel that typically runs with elevated privileges.

9.8 CVSS 3.1 Critical EPSS 55% · top 1.0% CWE-863 · Incorrect authorization
9.8CVSS 3.1 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityPre-auth network-reachable file write on an internet-facing control panel with a 9.8 CVSS score and high EPSS probability.

What it is

Control Web Panel (CWP) before 0.9.8.1107 mishandles authorization on the api/?api=add_server&DHCP= endpoint, allowing a crafted request to write an authorized_keys text file into the /resources/ folder. Because the endpoint is reachable without credentials, this is a pre-auth file-write primitive on a hosting control panel that typically runs with elevated privileges.

Impact

An attacker can place an attacker-controlled authorized_keys file on the server, which can lead to SSH key-based access and full compromise of the panel host. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network via a crafted HTTP request to the api/?api=add_server&DHCP= endpoint; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.55338 (99th percentile) and references include an Exploit-tagged third-party advisory describing pre-auth RCE, so public exploitation detail exists. No ransomware group usage is documented in the record.

What to do

  • Upgrade CWP to 0.9.8.1107 or later, per the vendor changelog.
  • Restrict network access to the CWP panel and its api/ endpoints to trusted management IPs.
  • Audit and remove unexpected authorized_keys files under /resources/ and other web-accessible paths.
  • Rotate SSH keys and credentials on any host that ran an affected CWP version.
  • Monitor the api/ endpoint for add_server and DHCP parameters in web logs.

Detection

  • Search web logs for requests to api/ containing api=add_server and DHCP= parameters.
  • Alert on creation or modification of authorized_keys files under /resources/ or other web-served directories.
  • Monitor for new or changed SSH authorized_keys entries and unexpected SSH logins on CWP hosts.
  • Baseline and review outbound or inbound connections to the CWP panel from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-45466 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-44877CWP Control Web Panel login parameter OS command injectionCWP (Control Web Panel, formerly CentOS Web Panel) 7 before 0.9.8.1147 passes the login parameter in login/index.php to a shell without sanitizing sh…KEVEPSS 100%analysed9.0CVE-2025-48703CWP Control Web Panel command injection in filemanager changePermCWP (Control Web Panel) before 0.9.8.1205 fails to sanitize the t_total parameter in a filemanager changePerm request, allowing shell metacharacters …KEVEPSS 100%analysed9.8CVE-2023-42121Control-webpanel webpanel missing authentication for critical function vulnerabilityControl Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…EPSS 1.5%9.8CVE-2021-45467CWP loader.php null-byte path bypass allows unauthenticated API key registrationControl Web Panel (CWP) before 0.9.8.1107 lets an unauthenticated attacker inject %00 bytes into the scripts parameter of /user/loader.php to travers…EPSS 71%analysed9.8CVE-2022-25046CWP loader.php path traversal allows remote code executionCWP (Control Web Panel) v0.9.8.1122 contains a path traversal flaw in loader.php that lets an unauthenticated attacker execute arbitrary code through…EPSS 57%analysed9.8CVE-2021-31316Control-webpanel webpanel sql injection vulnerabilityThe unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.EPSS 13%9.8CVE-2021-31324Control-webpanel webpanel os command injection vulnerabilityThe unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.EPSS 35%9.8CVE-2020-15623Control-webpanel webpanel vulnerabilityThis vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i…EPSS 8.3%

Source: NIST National Vulnerability Database (record CVE-2021-45466), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.