← back
CVE-2025-67888highCWE-78

CVE-2025-67888

56Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 7.3epss 3.6%
from disclosure to weapon0 days
Published on NVDMay 8
1st PoCDec 18
metasploitDec 16
exploitation probability
3.6%top 11% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized before being used to execute OS commands. This can be exploited by unauthenticated attackers to inject and execute arbitrary OS commands with the privileges of root on the web server. Softaculous or SitePad must be present.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.