ZeroHour

CVE-2025-12737

large

Admin-level command injection (RCE) in WSO2 Carbon Console

CVSS 3.1
8.4 high
EPSS
<1%p13
Published
()
Modified
AI analysis

CVE-2025-12737 is a command injection flaw (CWE-78) in the Carbon Console of multiple WSO2 products, where specific administrative operations fail to adequately validate user-supplied input. An attacker who already holds administrative privileges and has access to the Carbon Console can submit crafted input through these operations to inject and execute arbitrary code remotely. Successful exploitation yields full remote code execution and complete compromise of the host running the affected WSO2 product, so an attacker can move from an already-compromised or stolen admin session to owning the server. The flaw affects WSO2 API Manager, API Control Plane, Identity Server, Identity Server as Key Manager, Open Banking AM, Open Banking IAM, Traffic Manager, and Universal Gateway. As of now there is no known public proof-of-concept, it is not in CISA's KEV catalog, and EPSS puts short-term exploitation odds at roughly 0.2%.

What to do: Check the official WSO2 security advisory for CVE-2025-12737 and upgrade each affected product to the patched release it lists, since exact fixed versions are not provided in the available data. In the meantime, restrict Carbon Console (admin, typically port 9443) access to trusted admin networks via firewall/VPN rules, review and rotate administrative credentials for signs of compromise, and monitor the console logs for unusual administrative operations.

Affected
WSO2 API Manager
WSO2 API Control Plane
WSO2 Identity Server
WSO2 Identity Server as Key Manager
WSO2 Open Banking AM
WSO2 Open Banking IAM
WSO2 Traffic Manager
WSO2 Universal Gateway
Estimated exposure
largeLikely tens of thousands of deployments across the eight affected WSO2 product lines, with several thousand Carbon management consoles exposed to adjacent or… — Estimated from WSO2's broad enterprise footprint across API Manager and Identity Server product lines and public internet scans showing thousands of Carbon consoles (typically port 9443) reachable remotely, though the admin-privilege…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.

Vendors
wso2
Products
api control plane, api manager, identity server, identity server as key manager, open banking am, open banking iam, traffic manager, universal gateway
Weakness
CWE-78
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.