CVE-2025-67888
High
Published: 08 May 2026
Published
08 May 2026
Modified
08 May 2026
KEV Added
—
Patch
—
CVSS Score
7.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.0616
90.9th percentile
Risk Priority
18
60% EPSS · 20% KEV · 20% CVSS
Description
An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized before being used to execute OS commands. This can…
more
be exploited by unauthenticated attackers to inject and execute arbitrary OS commands with the privileges of root on the web server. Softaculous or SitePad must be present.
Likely Mitigating ControlsAI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Security SummaryAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)