PT-2025-22355 · Aapanel · Aapanel

Published

2025-05-21

·

Updated

2025-12-27

·

CVE-2024-42922

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AAPanel version 7.0.7
Description The issue is related to an OS command injection, which can lead to remote command execution (RCE). It is estimated that more than 3.6 million servers globally are potentially affected.
Recommendations For AAPanel version 7.0.7, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-42922

Affected Products

Aapanel