Vulnerability record · CVE-2022-25046 · published 7 July 2022
CVE-2022-25046: CWP loader.php path traversal allows remote code execution
Control Webpanel · Webpanel
CWP (Control Web Panel) v0.9.8.1122 contains a path traversal flaw in loader.php that lets an unauthenticated attacker execute arbitrary code through a crafted POST request. The vulnerability is remotely reachable with no privileges or user interaction, making it a severe risk for exposed panel instances.
Description
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, high EPSS, and public exploit references make this an urgent remote code execution risk for exposed CWP instances.
What it is
CWP (Control Web Panel) v0.9.8.1122 contains a path traversal flaw in loader.php that lets an unauthenticated attacker execute arbitrary code through a crafted POST request. The vulnerability is remotely reachable with no privileges or user interaction, making it a severe risk for exposed panel instances.
Impact
An attacker can run arbitrary code on the server, likely with the privileges of the web panel process, leading to full compromise of the hosting control panel and hosted sites. This can result in data theft, service disruption, or use of the host as a pivot point.
Attack surface
Reached over the network via HTTP POST to loader.php; the CVSS vector shows no authentication (PR:N) and no user interaction (UI:N) required. Any internet-exposed CWP instance running the affected version is a candidate target.
Exploitation
Not listed in CISA KEV, but EPSS is 0.578 (99th percentile) and public exploit code is referenced on GitHub, indicating active interest and likely weaponization. No ransomware group usage is documented in the record.
What to do
- Patch or upgrade CWP beyond v0.9.8.1122 as soon as a fixed release is available; treat the panel as untrusted until then.
- Restrict network access to the CWP panel (loader.php and admin interfaces) to trusted IPs or a VPN; do not expose it directly to the internet.
- Deploy a WAF rule to block path traversal patterns in POST requests to loader.php.
- Monitor and audit the web server account for unexpected file writes or process execution.
- If patching is not possible, consider temporarily disabling or isolating the affected panel component.
Detection
- Inspect web server and CWP logs for POST requests to loader.php containing traversal sequences such as ../ or encoded variants.
- Alert on unexpected child processes spawned by the web server or panel service.
- Monitor for new or modified files in web-accessible directories and panel configuration paths.
- Use file integrity monitoring on CWP installation directories to catch unauthorized changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/Immersive-Labs-Sec/CentOS-WebPanel | ExploitThird Party Advisory |
| https://github.com/Immersive-Labs-Sec/CentOS-WebPanel | ExploitThird Party Advisory |
Track CVE-2022-25046 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-25046), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.