PT-2023-5686 · Unknown · Control Web Panel

Muhammad Ikhsanudin

·

Published

2023-05-09

·

Updated

2025-08-09

·

CVE-2023-42121

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Control Web Panel (CWP) (affected versions not specified)
Description The issue is related to a lack of proper authentication in the web interface of Control Web Panel, allowing remote attackers to execute arbitrary code on affected installations. This can impact the confidentiality, integrity, and availability of protected information. The specific flaw exists within the implementation of authentication, resulting from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of a valid CWP user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Missing Authentication

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2023-06354
CVE-2023-42121
ZDI-23-1478

Affected Products

Control Web Panel