CVE-2025-12737
largeAdmin-level command injection (RCE) in WSO2 Carbon Console
CVE-2025-12737 is a command injection flaw (CWE-78) in the Carbon Console of multiple WSO2 products, where specific administrative operations fail to adequately validate user-supplied input. An attacker who already holds administrative privileges and has access to the Carbon Console can submit crafted input through these operations to inject and execute arbitrary code remotely. Successful exploitation yields full remote code execution and complete compromise of the host running the affected WSO2 product, so an attacker can move from an already-compromised or stolen admin session to owning the server. The flaw affects WSO2 API Manager, API Control Plane, Identity Server, Identity Server as Key Manager, Open Banking AM, Open Banking IAM, Traffic Manager, and Universal Gateway. As of now there is no known public proof-of-concept, it is not in CISA's KEV catalog, and EPSS puts short-term exploitation odds at roughly 0.2%.
What to do: Check the official WSO2 security advisory for CVE-2025-12737 and upgrade each affected product to the patched release it lists, since exact fixed versions are not provided in the available data. In the meantime, restrict Carbon Console (admin, typically port 9443) access to trusted admin networks via firewall/VPN rules, review and rotate administrative credentials for signs of compromise, and monitor the console logs for unusual administrative operations.
| WSO2 API Manager | — |
| WSO2 API Control Plane | — |
| WSO2 Identity Server | — |
| WSO2 Identity Server as Key Manager | — |
| WSO2 Open Banking AM | — |
| WSO2 Open Banking IAM | — |
| WSO2 Traffic Manager | — |
| WSO2 Universal Gateway | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.
- Vendors
- wso2
- Products
- api control plane, api manager, identity server, identity server as key manager, open banking am, open banking iam, traffic manager, universal gateway
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.