Cyber News / Article / CVE-2022-44877, critical RCE in CentOS Control Web Panel exploited in the wild: everything you need to know

CVE-2022-44877, critical RCE in CentOS Control Web Panel exploited in the wild: everything you need to know
Detect and mitigate CVE-2022-44877, a CentOS Control Web Panel (CWP) unauthenticated RCE exploited in the wild. Security teams are advised to patch urgently.
CVE-2022-44877, a critical RCE vulnerability in Control Web Panel 7 (also known as CentOS Web Panel), has been reportedly exploited in the wild. The vulnerability could allow an unauthenticated attacker to escalate privileges and execute code remotely on susceptible servers. Although the vulnerability was published and assigned a CVE on January 6, a fix has been available since October 25, 2022. It was assigned a CVSS score of 9.8.
Exploitation attempts reportedly began around January 6, closely following the publication of a publicproof of concept.
In unpatched versions of CWP, there is a flaw that allows the execution of Bash commands if double quotation marks are used when logging incorrect entries into the system. This flaw could enable an attacker to execute commands remotely on a machine running a vulnerable version of CWP, with the same privilege level as CWP, which in many cases isrootby default. This is the third critical vulnerability in CWP published in the past 30 days, along withCVE-2021-45467andCVE-2021-45466.
According to Wiz data, CWP is not prevalent in cloud environments and therefore there is a lower risk of CVE-2022-44877 exploitation in such environmets.
Since the publication of the proof of concept on January 6,mass exploitationattempts have beenobservedin the wild.
See the full post on
Researchers observedthe following IP addresses in attempted exploitations:
206.189.170.136
185.117.73.208
157.230.62.113
180.183.132.35
See the full post on
Versions of CentOS Control Web Panel prior to version0.9.8.1147.
It is highly recommended to update instances of CWP to the patched version0.9.8.1147, or later. In addition, monitor if your environments have been accessed by any aboveknown malicious IP address.
Wiz customers can use the pre-built query and advisory in the Wiz Threat Center to search for vulnerable instances in their environment.
CloudSEK blog
The Hacker News article
Proof of concept
Learn how to detect malicious persistence techniques in AWS, GCP & Azure after potential initial compromise, like with the CircleCI incident
Wiz announces availability of new regional data center and adds support for Essential Eight controls.
Hear from security leaders about their plans, strategies, and priorities for the new year.
Get a personalized demo
©2026Wiz, Inc.
StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings
Related articles
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
2 days ago
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
2 days ago
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
3 days ago
You might Also like

Windows BitLocker Vulnerability Allows Attackers to Execute Malicious Code Remotely

Man gets 15 years for extorting women with AI-generated porn videos

