Impact
CyberPanel 2.4.3 contains an authenticated remote code execution flaw in the backup feature that lets an attacker supply a malicious remote server address. By exploiting the unauthenticated SSH public key retrieval routine, the attacker can write a crafted key directly to /root/.ssh/authorized_keys. This grants the attacker persistent root-level SSH access to the machine. The weakness stems from improper validation during the key transfer stage, allowing an unauthenticated user to place arbitrary keys in an authorized list.
Affected Systems
The vulnerability affects all installations of CyberPanel 2.4.3. The vendor product is referenced as usmannasir:cyberpanel. Versions prior to the fix in the commit identified by eca0c3c are vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity; the exploit requires valid user credentials but can be performed remotely through the backup interface. The EPSS score is not available, so the likelihood of attack cannot be quantified, yet the lack of KEV listing suggests no known active exploitation. The attack path requires authenticated access to the admin console, followed by selection of a malicious remote backup server, resulting in root-level access.
OpenCVE Enrichment