LiveActive security incident?Get immediate response
CVE Record

CVE-2021-37840: aaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket...

aaPanel through 6.8.12 allows Cross-Site WebSocket Hijacking (CSWH) involving OS commands within WebSocket messages at a ws:// URL for /webssh (the victim must have configured Terminal with at least one host). Successful exploitation depends on the browser used by a potential victim (e.g., exploitation can occur with Firefox but not Chrome).

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2021-37840 is a browser-based attack against aaPanel through version 6.8.12. If Terminal/WebSSH has at least one host configured, a malicious page may be able to make the victim's browser send WebSocket messages that run OS commands. The public record notes browser dependency, with Firefox affected in the cited description and Chrome not affected there.

Executive priority

Prioritize review if aaPanel is used for server administration. This is not a broad internet worm scenario based on supplied evidence, but affected admin panels can expose server command execution through a browser-mediated path. Reduce exposure and confirm vendor remediation status promptly.

Technical view

The issue is Cross-Site WebSocket Hijacking in aaPanel's /webssh endpoint over ws://. The vulnerability involves OS commands inside WebSocket messages and requires a victim environment where Terminal has at least one host configured. Public metadata does not provide CVSS, CWE, complete affected CPEs, or a vendor-confirmed remediation path.

Likely exposure

Exposure is limited to aaPanel deployments through 6.8.12 using the Terminal/WebSSH feature with at least one configured host. Risk increases where administrators browse untrusted sites from a browser that permits the attack pattern while authenticated to aaPanel.

Exploitation context

The CVE is not listed as KEV, and the supplied sources do not prove active exploitation. The issue is serious because successful exploitation can cross from a browser interaction into OS command execution through WebSSH, but success depends on user state, Terminal configuration, and browser behavior.

Researcher notes

Evidence is sparse in the CVE metadata: no CVSS vector, CWE, CPE, or explicit patch statement is supplied. The strongest technical signal is the /webssh CSWH path involving OS command messages and the environmental requirement for a configured Terminal host. Avoid assuming exploit reliability across browsers.

Mitigation direction

  • Identify aaPanel instances and confirm whether versions are 6.8.12 or older.
  • Disable or restrict Terminal/WebSSH where it is not operationally required.
  • Check aaPanel vendor guidance for fixed versions or official workarounds.
  • Restrict aaPanel administrative access to trusted networks or VPN paths.
  • Separate administrative browsing from general web browsing on affected environments.

Validation and detection

  • Inventory aaPanel version and confirm whether Terminal/WebSSH is enabled.
  • Check whether Terminal has at least one configured host.
  • Review access controls for aaPanel administrative interfaces.
  • Review logs for unexpected WebSSH activity or OS command execution.
  • Confirm browser exposure assumptions for administrative users.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-37840 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.