CVE-2024-12828 (CVSS 9.9): Webmin Vulnerability Leaves a Million Servers Exposed to RCE

Share:

The popular web-based system administration tool, Webmin, has been found to harbor a critical security vulnerability (CVE-2024-12828) that could allow attackers to seize control of servers. With an estimated one million installations worldwide, the impact of this vulnerability could be widespread.

The vulnerability, assigned a CVSS score of 9.9, stems from a command injection flaw within Webmin’s CGI request handling. Essentially, the software fails to properly sanitize user-supplied input, enabling attackers to inject malicious commands that are then executed with root privileges.

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required to exploit this vulnerability,” the advisory notes.

What makes this vulnerability particularly dangerous is that it can be exploited by less-privileged Webmin users. This means that even if an attacker doesn’t have full administrative access, they could potentially escalate their privileges and take complete control of the server.

The exploitability of CVE-2024-12828 could have devastating consequences, including:

  • Full server compromise
  • Unauthorized access to sensitive data
  • Deployment of malicious scripts and ransomware
  • Use of compromised servers as platforms for further attacks

The vulnerability was discovered by Trend Micro’s Zero Day Initiative and has been addressed in Webmin version 2.111. All Webmin and Virtualmin administrators are strongly urged to update their installations immediately.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:55 am, Jun 11, 2025
weather icon 14°C
L: 11° | H: 15°
overcast clouds
Humidity: 87 %
Pressure: 1020 mb
Wind: 10 mph ESE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:16 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
11° | 15°°C 0 mm 0% 12 mph 87 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
14° | 25°°C 0.35 mm 35% 12 mph 77 % 1016 mb 0 mm/h
Fri Jun 13 10:00 pm
weather icon
16° | 27°°C 0.5 mm 50% 11 mph 86 % 1020 mb 0 mm/h
Sat Jun 14 10:00 pm
weather icon
17° | 23°°C 0.21 mm 21% 14 mph 90 % 1020 mb 0 mm/h
Sun Jun 15 10:00 pm
weather icon
13° | 22°°C 0.22 mm 22% 9 mph 85 % 1025 mb 0 mm/h
Today 7:00 am
weather icon
14° | 14°°C 0 mm 0% 6 mph 87 % 1020 mb 0 mm/h
Today 10:00 am
weather icon
16° | 19°°C 0 mm 0% 7 mph 85 % 1020 mb 0 mm/h
Today 1:00 pm
weather icon
19° | 22°°C 0 mm 0% 8 mph 74 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
25° | 25°°C 0 mm 0% 11 mph 49 % 1018 mb 0 mm/h
Today 7:00 pm
weather icon
22° | 22°°C 0 mm 0% 12 mph 56 % 1017 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 10 mph 67 % 1017 mb 0 mm/h
Tomorrow 1:00 am
weather icon
15° | 15°°C 0 mm 0% 9 mph 70 % 1016 mb 0 mm/h
Tomorrow 4:00 am
weather icon
14° | 14°°C 0 mm 0% 8 mph 69 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€95,925.15
0.09%
Ethereum(ETH)
€2,445.27
3.89%
Tether(USDT)
€0.87
-0.03%
XRP(XRP)
€2.00
-0.16%
Solana(SOL)
€144.49
3.78%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.173612
2.88%
Shiba Inu(SHIB)
€0.000011
2.26%
Pepe(PEPE)
€0.000011
1.63%
Peanut the Squirrel(PNUT)
€0.251899
1.40%
Scroll to Top