CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
https://www.securityweek.com/pcpjack-worm-removes-teampcp-infections-steals-credentials/
https://thehackernews.com/2026/05/pcpjack-credential-stealer-exploits-5.html
https://www.securityweek.com/cisa-warns-of-cwp-vulnerability-exploited-in-the-wild/
https://github.com/137f/PoC-CVE-2025-48703
https://github.com/itstarsec/CVE-2025-48703
https://github.com/trh4ckn0n/CVE-2025-48703
https://github.com/PuddinCat/GithubRepoSpider
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-48703
https://fenrisk.com/rce-centos-webpanel