Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CISA Warns of CWP Vulnerability Exploited in the Wild

CISA Warns of CWP Vulnerability Exploited in the Wild

Posted on November 5, 2025November 5, 2025 By CWS

The cybersecurity company CISA on Tuesday warned {that a} important vulnerability affecting the Management Internet Panel (CWP) server administration software program has been exploited within the wild.

CWP, beforehand named CentOS Internet Panel, is a free and extensively used Linux webhosting management panel that’s designed to simplify server administration.

A vulnerability in CWP, tracked as CVE-2025-48703, permits distant, unauthenticated attackers to execute arbitrary instructions on weak techniques. An attacker in possession of a sound non-root username can bypass authentication and execute instructions utilizing specifically crafted requests. 

The vulnerability was reported to CWP builders in mid-Might and patched roughly one month later with the discharge of model 0.9.8.1205.

There don’t look like any public experiences describing assaults by which CVE-2025-48703 has been exploited. 

Findsec warned just a few months in the past that exploitation of the vulnerability had been imminent. The corporate famous that exploitation could possibly be automated and that risk actors had already began growing and sharing exploits on cybercrime boards.

In response to Netlas.io, there are roughly 150,000 internet-exposed CWP situations which can be probably affected by CVE-2025-48703, a majority in the US (37,510), adopted by Germany, Japan, India, France, and Canada. Shodan exhibits greater than 220,000 internet-exposed situations. 

Given this widespread publicity, it’s extremely doubtless that the vulnerability has been exploited in opportunistic assaults. Commercial. Scroll to proceed studying.

CISA added CVE-2025-48703 to its Recognized Exploited Vulnerabilities (KEV) catalog and instructed federal companies to handle it by November 25. 

In-the-wild exploitation of a CWP vulnerability was beforehand reported in early 2023. 

Associated: Essential Flaw in Standard React Native NPM Bundle Exposes Builders to Assaults

Associated: CISA Warns of Exploited DELMIA Manufacturing facility Software program Vulnerabilities

Associated: CISA Provides Exploited XWiki, VMware Flaws to KEV Catalog

Security Week News Tags:CISA, CWP, Exploited, Vulnerability, Warns, Wild

Post navigation

Previous Post: CISA Adds Gladinet and CWP Flaws to KEV Catalog Amid Active Exploitation Evidence
Next Post: US Sanctions North Korean Bankers Accused of Laundering Stolen Cryptocurrency

Related Posts

New HTTP Request Smuggling Attacks Impacted CDNs, Major Orgs, Millions of Websites New HTTP Request Smuggling Attacks Impacted CDNs, Major Orgs, Millions of Websites Security Week News
Vulnerability in Adobe Extension Risked WhatsApp Data Exposure Vulnerability in Adobe Extension Risked WhatsApp Data Exposure Security Week News
CISO Conversations: Keith McCammon, CSO and Co-founder at Red Canary CISO Conversations: Keith McCammon, CSO and Co-founder at Red Canary Security Week News
Sangoma Patches Critical Zero-Day Exploited to Hack FreePBX Servers Sangoma Patches Critical Zero-Day Exploited to Hack FreePBX Servers Security Week News
Arkanix Stealer Malware Ceases Operations Quickly Arkanix Stealer Malware Ceases Operations Quickly Security Week News
Fake Claude Site Distributes RAT via Trojan Installer Fake Claude Site Distributes RAT via Trojan Installer Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark