← Vulnerability feed

Vulnerability record · CVE-2022-25046 · published 7 July 2022

CVE-2022-25046: CWP loader.php path traversal allows remote code execution

Control Webpanel · Webpanel

CWP (Control Web Panel) v0.9.8.1122 contains a path traversal flaw in loader.php that lets an unauthenticated attacker execute arbitrary code through a crafted POST request. The vulnerability is remotely reachable with no privileges or user interaction, making it a severe risk for exposed panel instances.

9.8 CVSS 3.1 Critical EPSS 57% · top 0.9% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 10.0
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or interaction required, high EPSS, and public exploit references make this an urgent remote code execution risk for exposed CWP instances.

What it is

CWP (Control Web Panel) v0.9.8.1122 contains a path traversal flaw in loader.php that lets an unauthenticated attacker execute arbitrary code through a crafted POST request. The vulnerability is remotely reachable with no privileges or user interaction, making it a severe risk for exposed panel instances.

Impact

An attacker can run arbitrary code on the server, likely with the privileges of the web panel process, leading to full compromise of the hosting control panel and hosted sites. This can result in data theft, service disruption, or use of the host as a pivot point.

Attack surface

Reached over the network via HTTP POST to loader.php; the CVSS vector shows no authentication (PR:N) and no user interaction (UI:N) required. Any internet-exposed CWP instance running the affected version is a candidate target.

Exploitation

Not listed in CISA KEV, but EPSS is 0.578 (99th percentile) and public exploit code is referenced on GitHub, indicating active interest and likely weaponization. No ransomware group usage is documented in the record.

What to do

  • Patch or upgrade CWP beyond v0.9.8.1122 as soon as a fixed release is available; treat the panel as untrusted until then.
  • Restrict network access to the CWP panel (loader.php and admin interfaces) to trusted IPs or a VPN; do not expose it directly to the internet.
  • Deploy a WAF rule to block path traversal patterns in POST requests to loader.php.
  • Monitor and audit the web server account for unexpected file writes or process execution.
  • If patching is not possible, consider temporarily disabling or isolating the affected panel component.

Detection

  • Inspect web server and CWP logs for POST requests to loader.php containing traversal sequences such as ../ or encoded variants.
  • Alert on unexpected child processes spawned by the web server or panel service.
  • Monitor for new or modified files in web-accessible directories and panel configuration paths.
  • Use file integrity monitoring on CWP installation directories to catch unauthorized changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-25046 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-44877CWP Control Web Panel login parameter OS command injectionCWP (Control Web Panel, formerly CentOS Web Panel) 7 before 0.9.8.1147 passes the login parameter in login/index.php to a shell without sanitizing sh…KEVEPSS 100%analysed9.0CVE-2025-48703CWP Control Web Panel command injection in filemanager changePermCWP (Control Web Panel) before 0.9.8.1205 fails to sanitize the t_total parameter in a filemanager changePerm request, allowing shell metacharacters …KEVEPSS 100%analysed9.8CVE-2023-42121Control-webpanel webpanel missing authentication for critical function vulnerabilityControl Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on…EPSS 1.5%9.8CVE-2021-45466CWP pre-auth request lets attacker plant authorized_keys fileControl Web Panel (CWP) before 0.9.8.1107 mishandles authorization on the api/?api=add_server&DHCP= endpoint, allowing a crafted request to write an …EPSS 55%analysed9.8CVE-2021-45467CWP loader.php null-byte path bypass allows unauthenticated API key registrationControl Web Panel (CWP) before 0.9.8.1107 lets an unauthenticated attacker inject %00 bytes into the scripts parameter of /user/loader.php to travers…EPSS 71%analysed9.8CVE-2021-31316Control-webpanel webpanel sql injection vulnerabilityThe unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.EPSS 13%9.8CVE-2021-31324Control-webpanel webpanel os command injection vulnerabilityThe unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.EPSS 35%9.8CVE-2020-15623Control-webpanel webpanel vulnerabilityThis vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i…EPSS 8.3%

Source: NIST National Vulnerability Database (record CVE-2022-25046), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.