Two bugs affecting the CWP software can be exploited by unauthenticated attackers to remotely execute code as root on vulnerable Linux servers.

See also: Significant increase in malware targeting Linux machines in 2021
CWP, formerly known as CentOS Web Panel, is a free Linux control panel for managing dedicated web hosting servers and virtual private servers.
The two bugs identified in CWP by Paulos Yibelo of Octagon Networksare a file inclusion vulnerability (CVE-2021-45467) and a file write error (CVE-2021-45466) that lead to remote access when connected to each other.
In short, successful exploitation requires bypassing security protections to allow attackers to reach the restricted API without authentication.
This can be done by registering an API key using the file inclusion flaw and creating a malicious authorized_keys on the server, using the file write flaw.
See also: Amazon server outage causes problems for Netflix, Ring and deliveries

While the file inclusion bug CVE-2021-45467 has been fixed, Octagon Networks says that “some people were able to reverse engineer the patch and exploit some servers.”
The security researchers also said they will release a proof-of-concept exploit for the bugs after several Linux servers running CWP are upgraded to the latest version.
According to the CWP developers, their software supports the following operating systems: CentOS, Rocky Linux, Alma Linux , and Oracle Linux.
See also: Linux Mint 20.3 will receive security updates until 2025
While the CWP website claims that around 30,000 servers are running CWP, there are nearly 80,000 CWP servers exposed online at BinaryEdge, according to Bleeping Computer.
Over 200,000 can also be found on Shodan and Censys, according to the researchers who discovered the RCE chain.
