Impact
ThemisNETPanel allows an unauthenticated attacker to upload and execute arbitrary PHP files by posting a base64‑encoded payload to an unsecured endpoint. The lack of authentication makes the vulnerability a direct path to remote code execution, taking full control of the underlying server. The weakness is classified as CWE‑306 'Missing Authentication'.
Affected Systems
ThemisNETPanel, developed by 4real, is affected in all releases prior to the April 2026 patch. No other versions have been confirmed to contain the flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, indicating critical severity. Exploitation requires only an unauthenticated HTTP POST to the upload URL; no privileged access is needed. The EPSS score of < 1% suggests a very low but nonzero exploitation probability; the lack of authentication increases the risk, but no publicly documented exploit is indicated by the data provided. The issue is not currently listed in the CISA KEV catalog, but the potential impact warrants immediate remediation.
OpenCVE Enrichment