<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — CWP</title><description>Actively exploited vulnerabilities affecting CWP products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/cwp.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-48703 — CWP Control Web Panel OS Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-48703</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-48703</guid><description>CWP Control Web Panel, a widely used web hosting control panel, has a critical flaw allowing attackers with no credentials to execute arbitrary operating system commands remotely. The only prerequisite is knowing a valid non-root username on the system — information often obtainable through other means. Successful exploitation gives an attacker full command execution on the server, putting hosted websites, databases, and the underlying infrastructure at serious risk of compromise or ransomware deployment.</description><pubDate>Tue, 04 Nov 2025 00:00:00 GMT</pubDate><category>CWP</category><category>Control Web Panel</category></item></channel></rss>