← Vulnerability feed

Vulnerability record · CVE-2023-42121 · published 3 May 2024

CVE-2023-42121: Control-webpanel webpanel missing authentication for critical function vulnerability

Control Webpanel · Webpanel

Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of authentication within the web interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of a valid CWP user. Was ZDI-CAN-20582.

9.8 CVSS 3.0 Critical EPSS 1.5% · top 27.3% CWE-306 · Missing authentication for critical function
9.8CVSS 3.0 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Control Web Panel Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Control Web Panel. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of authentication within the web interface. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of a valid CWP user. Was ZDI-CAN-20582.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-42121 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-44877CWP Control Web Panel login parameter OS command injectionCWP (Control Web Panel, formerly CentOS Web Panel) 7 before 0.9.8.1147 passes the login parameter in login/index.php to a shell without sanitizing sh…KEVEPSS 100%analysed9.0CVE-2025-48703CWP Control Web Panel command injection in filemanager changePermCWP (Control Web Panel) before 0.9.8.1205 fails to sanitize the t_total parameter in a filemanager changePerm request, allowing shell metacharacters …KEVEPSS 100%analysed9.8CVE-2021-45466CWP pre-auth request lets attacker plant authorized_keys fileControl Web Panel (CWP) before 0.9.8.1107 mishandles authorization on the api/?api=add_server&DHCP= endpoint, allowing a crafted request to write an …EPSS 55%analysed9.8CVE-2021-45467CWP loader.php null-byte path bypass allows unauthenticated API key registrationControl Web Panel (CWP) before 0.9.8.1107 lets an unauthenticated attacker inject %00 bytes into the scripts parameter of /user/loader.php to travers…EPSS 71%analysed9.8CVE-2022-25046CWP loader.php path traversal allows remote code executionCWP (Control Web Panel) v0.9.8.1122 contains a path traversal flaw in loader.php that lets an unauthenticated attacker execute arbitrary code through…EPSS 57%analysed9.8CVE-2021-31316Control-webpanel webpanel sql injection vulnerabilityThe unprivileged user portal part of CentOS Web Panel is affected by a SQL Injection via the 'idsession' HTTP POST parameter.EPSS 13%9.8CVE-2021-31324Control-webpanel webpanel os command injection vulnerabilityThe unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.EPSS 35%9.8CVE-2020-15623Control-webpanel webpanel vulnerabilityThis vulnerability allows remote attackers to write arbitrary files on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication i…EPSS 8.3%

Source: NIST National Vulnerability Database (record CVE-2023-42121), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.