๐Ÿ” CVE Alert

CVE-2025-34429

UNKNOWN 0.0

1Panel CSRF Web Port Configuration Change

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality. The port-change endpoint lacks CSRF defenses such as anti-CSRF tokens or Origin/Referer validation. An attacker can craft a malicious webpage that submits a port-change request; when a victim visits it while authenticated, the browser includes valid session cookies and the request succeeds. This allows an attacker to change the port on which the 1Panel web service listens, causing loss of access on the original port and resulting in service disruption or denial of service, and may unintentionally expose the service on an attacker-chosen port.

CWE CWE-352
Vendor lxware
Product 1panel
Published Dec 10, 2025
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for lxware 1panel

Be the first to know when new unknown vulnerabilities affecting lxware 1panel are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

LXware / 1Panel
1.10.33 โ‰ค 2.0.15

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/1Panel-dev/1Panel/releases 1panel.pro: https://1panel.pro/ vulncheck.com: https://www.vulncheck.com/advisories/1panel-csrf-web-port-configuration-change

Credits

av01t3x