Vulnerability record · CVE-2021-45467 · published 26 December 2022
CVE-2021-45467: CWP loader.php null-byte path bypass allows unauthenticated API key registration
Control Webpanel · Webpanel
Control Web Panel (CWP) before 0.9.8.1107 lets an unauthenticated attacker inject %00 bytes into the scripts parameter of /user/loader.php to traverse into internal API scripts such as api/account_new_create. This bypasses authorization and lets the attacker register an arbitrary API key, which the referenced exploit write-up describes as leading to pre-auth remote code execution.
Description
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be used, e.g., .%00%00%00./.%00%00%00./api/account_new_create could also be used for the scripts parameter.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable flaw with a 9.8 CVSS score, public exploit write-up, and very high EPSS indicating likely active exploitation.
What it is
Control Web Panel (CWP) before 0.9.8.1107 lets an unauthenticated attacker inject %00 bytes into the scripts parameter of /user/loader.php to traverse into internal API scripts such as api/account_new_create. This bypasses authorization and lets the attacker register an arbitrary API key, which the referenced exploit write-up describes as leading to pre-auth remote code execution.
Impact
An attacker gains the ability to register an API key without credentials, which the exploit reference indicates can be leveraged to execute code on the panel host. That yields full compromise of the web hosting control panel and the accounts it manages.
Attack surface
Reachable over the network via HTTP requests to /user/loader.php with a crafted scripts parameter; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The flaw is a missing authorization check combined with null-byte path handling.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.70745, 99.4th percentile) and the references include an Exploit-tagged third-party advisory describing pre-auth RCE, so public exploitation guidance exists.
What to do
- Upgrade CWP to 0.9.8.1107 or later immediately; the vendor changelog is the authoritative source for the fixed build.
- If immediate upgrade is not possible, restrict access to /user/loader.php and the CWP panel to trusted management networks only.
- Block or reject HTTP requests containing %00 (null byte) sequences at the reverse proxy or WAF.
- Audit CWP for unexpected API keys and revoke any that cannot be accounted for.
- Monitor vendor advisories for follow-up fixes, since the record notes only a minimum fixed version.
Detection
- Search web/proxy logs for requests to /user/loader.php containing %00 or repeated null-byte sequences in the scripts parameter.
- Alert on requests to /user/loader.php with scripts values referencing api/account_new_create or other internal API paths.
- Review CWP API key listings and creation events for keys created outside change windows or by unknown sources.
- Correlate panel access logs with process execution on the host for unexpected commands following loader.php requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://control-webpanel.com/changelog | Release NotesVendor Advisory |
| https://octagon.net/blog/2022/01/22/cve-2021-45467-cwp-centos-web-panel-preauth-rce/ | ExploitThird Party Advisory |
| https://control-webpanel.com/changelog | Release NotesVendor Advisory |
| https://octagon.net/blog/2022/01/22/cve-2021-45467-cwp-centos-web-panel-preauth-rce/ | ExploitThird Party Advisory |
Track CVE-2021-45467 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-45467), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.