January 17, 2023 · Applied Cybernetics Group
CVE-2022-44877 — CWP Control Web Panel
CWP Control Web Panel OS Command Injection Vulnerability
- Added to KEV
2023-01-17- Federal due date
2023-02-07- Vendor
- CWP
- Product
- Control Web Panel
- EPSS
- 100.0th percentile (score 0.945, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-44877
CISA short description
CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote attackers to execute commands via shell metacharacters in the login parameter.
Required action
Apply updates per vendor instructions.