Hackers are exploiting a major flaw that was recently patched in the Control Web Panel (CWP), formerly known as CentOS Web Panel, a tool for managing servers.
See also: Cisco warns of critical vulnerability in EoL routers

The security flaw, CVE-2022-44877, has received a worrying severity rating of 9.8 out of 10, due to the fact that it gives a malicious actor access to execute code remotely without authentication.
The exploit code is immediately available
On January 3, Numan Türle of Gais Cyber Security publicly released data and a demonstration video illustrating the issue he uncovered in October. His proof-of-concept (PoC) exploit demonstrated the vulnerability's power to manipulate digital systems.
Just three days after the security flaw was discovered, hackers had already begun exploiting it to gain unauthorized access to unpatched systems and identify other vulnerable machines.
On October 25, 2022, version 0.9.8.1147 of the Control Web Panel was released to address the security vulnerability posed by CVE-2022-44877, to which previous versions of the panel were vulnerable.
See also: Scattered Spider: Trying to avoid detection with the Bring-Your-Own-Driver tactic
A technical analysis of the PoC exploit code is available from CloudSek, which performed a search for CWP servers on the Shodan platform and found more than 400,000 CWP instances accessible over the Internet.

Daily scans conducted by the Shadowserver Foundation revealed that approximately 38,000 CWP instances are being exploited on a regular basis.
This number indicates the total number of machines monitored by the platform, regardless of their sensitivity status.

According to Shadowserver data collected and shared with BleepingComputer, cybercriminals are discovering vulnerable systems and using CVE-2022-44877 to create a terminal for communication between the two machines.
In some malicious attacks, hackers use the exploit to launch a reverse shell. The encoded payloads are converted into Python that call the attacker's machine and create a terminal on the vulnerable host with the help of the Python pty Module.
Some of the attacks were simply aimed at identifying vulnerable systems. It remains a mystery whether these scans are initiated by security researchers or by cybercriminals looking for machines they can exploit in the near future.
See also: Google Play Store and App Store are filled with fake ChatGPT apps
It appears that these exploitation attempts are derived from Numan Türle's publicly available PoC, with minor changes to meet the malicious actor.
GreyNoise's research uncovered multiple attacks on unpatched CWP hosts from IP addresses located in the US, Thailand , and the Netherlands.
Leveraging CVE-2022-44877 is easy, and with the exploit code already public, all hackers is find vulnerable targets, a painless job.
Administrators should take immediate action and update CWP to the latest available version, currently 0.9.8.1148 which is released on December 1, 2022.
Information source: bleepingcomputer.com
