← Vulnerability feed

Vulnerability record · CVE-2021-45467 · published 26 December 2022

CVE-2021-45467: CWP loader.php null-byte path bypass allows unauthenticated API key registration

Control Webpanel · Webpanel

Control Web Panel (CWP) before 0.9.8.1107 lets an unauthenticated attacker inject %00 bytes into the scripts parameter of /user/loader.php to traverse into internal API scripts such as api/account_new_create. This bypasses authorization and lets the attacker register an arbitrary API key, which the referenced exploit write-up describes as leading to pre-auth remote code execution.

9.8 CVSS 3.1 Critical EPSS 71% · top 0.6% CWE-862 · Missing authorization
9.8CVSS 3.1 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be used, e.g., .%00%00%00./.%00%00%00./api/account_new_create could also be used for the scripts parameter.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable flaw with a 9.8 CVSS score, public exploit write-up, and very high EPSS indicating likely active exploitation.

What it is

Control Web Panel (CWP) before 0.9.8.1107 lets an unauthenticated attacker inject %00 bytes into the scripts parameter of /user/loader.php to traverse into internal API scripts such as api/account_new_create. This bypasses authorization and lets the attacker register an arbitrary API key, which the referenced exploit write-up describes as leading to pre-auth remote code execution.

Impact

An attacker gains the ability to register an API key without credentials, which the exploit reference indicates can be leveraged to execute code on the panel host. That yields full compromise of the web hosting control panel and the accounts it manages.

Attack surface

Reachable over the network via HTTP requests to /user/loader.php with a crafted scripts parameter; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The flaw is a missing authorization check combined with null-byte path handling.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.70745, 99.4th percentile) and the references include an Exploit-tagged third-party advisory describing pre-auth RCE, so public exploitation guidance exists.

What to do

  • Upgrade CWP to 0.9.8.1107 or later immediately; the vendor changelog is the authoritative source for the fixed build.
  • If immediate upgrade is not possible, restrict access to /user/loader.php and the CWP panel to trusted management networks only.
  • Block or reject HTTP requests containing %00 (null byte) sequences at the reverse proxy or WAF.
  • Audit CWP for unexpected API keys and revoke any that cannot be accounted for.
  • Monitor vendor advisories for follow-up fixes, since the record notes only a minimum fixed version.

Detection

  • Search web/proxy logs for requests to /user/loader.php containing %00 or repeated null-byte sequences in the scripts parameter.
  • Alert on requests to /user/loader.php with scripts values referencing api/account_new_create or other internal API paths.
  • Review CWP API key listings and creation events for keys created outside change windows or by unknown sources.
  • Correlate panel access logs with process execution on the host for unexpected commands following loader.php requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-45467 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-44877CWP Control Web Panel login parameter OS command injectionCWP (Control Web Panel, formerly CentOS Web Panel) 7 before 0.9.8.1147 passes the login parameter in login/index.php to a shell without sanitizing sh…KEVEPSS 100%analysed9.0CVE-2025-48703CWP Control Web Panel command injection in filemanager changePermCWP (Control Web Panel) before 0.9.8.1205 fails to sanitize the t_total parameter in a filemanager changePerm request, allowing shell metacharacters …KEVEPSS 100%analysed9.8CVE-2023-42121Control-webpanel webpanel missing authentication for critical function vulnerabilityControl Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…EPSS 1.5%9.8CVE-2021-45466CWP pre-auth request lets attacker plant authorized_keys fileControl Web Panel (CWP) before 0.9.8.1107 mishandles authorization on the api/?api=add_server&DHCP= endpoint, allowing a crafted request to write an …EPSS 55%analysed9.8CVE-2022-25046CWP loader.php path traversal allows remote code executionCWP (Control Web Panel) v0.9.8.1122 contains a path traversal flaw in loader.php that lets an unauthenticated attacker execute arbitrary code through…EPSS 57%analysed9.8CVE-2021-31316Control-webpanel webpanel sql injection vulnerabilityThe unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.EPSS 13%9.8CVE-2021-31324Control-webpanel webpanel os command injection vulnerabilityThe unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.EPSS 35%9.8CVE-2020-15623Control-webpanel webpanel vulnerabilityThis vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i…EPSS 8.3%

Source: NIST National Vulnerability Database (record CVE-2021-45467), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.