FortiGuard Labs is aware of a report that a patched but critical vulnerability in Control Web Panel (CWP) is being exploited in the wild. The vulnerability (CVE-2022-44877) is a command injection vulnerability that allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter. Proof-of-concept code is reportedly available.Control Web Panel (formerly CentOS web panel) is a server administration user interface used to manage Linux systems.Why is this Significant?This is significant because a critical vulnerability in Control Web Panel (CVE-2022-44877) is being exploited in the wild. Previously known as “CentOS Web Panel”, Control Web Panel is a popular web-based server configuration software.Furthermore, CISA added CVE-2022-44877 to the known exploited vulnerabilities catalog on January 17, 2023. As proof-of-concept code is reportedly available, exploit attempts are expected to pick up.What is CVE-2022-44877?CVE-2022-44877 is a command injection vulnerability that allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter. The vulnerability is rated critical and has a CVSS score of 9.8.What Versions of Control Web Panel are Vulnerable?Control Web Panel 7 prior to version 0.9.8.1147 are vulnerable.Has the Vendor Released a Patch for CVE-2022-44877?Yes, a patch was released in version 0.9.8.1147 on October 25, 2022.What is the Status of Protection?FortiGuard Labs released the following IPS signature in version 22.480 for CVE-2022-44877:CentOS.Web.Panel.login.Command.Injection (default action is set to “pass”)
More Stories
zabbix-6.0.39-1.fc40
FEDORA-2025-d4263ef3ef Packages in this update: zabbix-6.0.39-1.fc40 Update description: Update to 6.0.39 (CVE-2024-45700, CVE-2024-36469, CVE-2024-42325, CVE-2024-45699) Read More
cri-o1.31-1.31.7-1.fc43
FEDORA-2025-556d8c02d7 Packages in this update: cri-o1.31-1.31.7-1.fc43 Update description: Automatic update for cri-o1.31-1.31.7-1.fc43. Changelog * Wed Apr 2 2025 Bradley G...
zabbix-7.2.5-1.fc42
FEDORA-2025-700a59e277 Packages in this update: zabbix-7.2.5-1.fc42 Update description: Update to 7.2.5 (CVE-2024-36469, CVE-2024-42325, CVE-2024-45700) Read More
zabbix7.0-7.0.11-1.el8
FEDORA-EPEL-2025-01e745cb85 Packages in this update: zabbix7.0-7.0.11-1.el8 Update description: Update to 7.0.11 CVE-2024-36465, CVE-2024-36469, CVE-2024-42325, CVE-2024-45699, CVE-2024-45700 Re-install SELinux module in...
zabbix7.0-7.0.11-1.el9
FEDORA-EPEL-2025-80a466f7f5 Packages in this update: zabbix7.0-7.0.11-1.el9 Update description: Update to 7.0.11 CVE-2024-36465, CVE-2024-36469, CVE-2024-42325, CVE-2024-45699, CVE-2024-45700 Re-install SELinux module in...
zabbix6.0-6.0.39-1.el8
FEDORA-EPEL-2025-77875be662 Packages in this update: zabbix6.0-6.0.39-1.el8 Update description: Update to 6.0.39 CVE-2024-45700, CVE-2024-36469, CVE-2024-42325, CVE-2024-45699 Fix selinux module name in...