CWP (Control Web Panel) < 0.9.8.1205 contains a remote code execution caused by shell metacharacters in the t_total parameter in filemanager changePerm request, letting unauthenticated attackers execute code remotely, exploit requires knowledge of a valid non-root username.
id: CVE-2025-48703
info:
name: CWP (Control Web Panel) < 0.9.8.1205 - Remote Code Execution
aut
...