Critical severity9.8CISA KEVNVD Advisory· Published Jan 5, 2023· Updated Jun 17, 2026
CVE-2022-44877
CVE-2022-44877
Description
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- CWP/Control Web Paneldescription
- Range: <0.9.8.1147
- Range: <0.9.8.1147
Patches
Vulnerability mechanics
References
7- packetstormsecurity.com/files/170388/Control-Web-Panel-7-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/170820/Control-Web-Panel-Unauthenticated-Remote-Command-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/171725/Control-Web-Panel-7-CWP7-0.9.8.1147-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2023/Jan/1nvdExploitMailing ListThird Party Advisory
- gist.github.com/numanturle/c1e82c47f4cba24cff214e904c227386nvdExploitThird Party Advisory
- www.youtube.com/watchnvdExploitThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
1- TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted DevelopmentUnit 42 · Jul 15, 2026