Hackers have begun exploiting a critical remote code execution vulnerability in unpatched versions of the Control Web Panel, a widely used web hosting interface
Patch NOW Ionut Arghire / SecurityWeek : Exploitation of Control Web Panel Vulnerability Starts After PoC Publication TechRadar : Hackers target and exploit major Control Web Panel security flaw Msmash / Slashdot : Vulnerability With 9.8 Severity in Control Web Panel is Under Active Exploit Tweets: Chris Wysopal / @weldpond : Today's Example of the 20% of apps with a critical vuln “login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter” https://thehackernews.com/... Rob Joyce / @nsa_csdirector : Active exploitation of Centos Control Web Panel through CVE-2022-44877. Patch issued in Oct. Exploitation is picking up. Attackers can get elevated privileges and remote code execution, leading to dangerous exploitation. Close down this vulnerability. https://arstechnica.com/...