CVE-2025-12737

Summary

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely.

Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.

Affected Software

VendorProductVersion RangeStatus
WSO2WSO2 Open Banking AM0 < 2.0.0unknown
WSO2WSO2 Open Banking AM2.0.0 < 2.0.0.398affected
WSO2WSO2 Open Banking IAM0 < 2.0.0unknown
WSO2WSO2 Open Banking IAM2.0.0 < 2.0.0.418affected
WSO2WSO2 Traffic Manager4.5.0 < 4.5.0.34affected
WSO2WSO2 Traffic Manager4.6.0 < 4.6.0.1affected
WSO2WSO2 Universal Gateway4.5.0 < 4.5.0.34affected
WSO2WSO2 Universal Gateway4.6.0 < 4.6.0.1affected
WSO2WSO2 API Control Plane4.5.0 < 4.5.0.36affected
WSO2WSO2 API Control Plane4.6.0 < 4.6.0.1affected
WSO2WSO2 API Manager0 < 3.1.0unknown
WSO2WSO2 API Manager3.1.0 < 3.1.0.349affected
WSO2WSO2 API Manager3.2.0 < 3.2.0.453affected
WSO2WSO2 API Manager3.2.1 < 3.2.1.73affected
WSO2WSO2 API Manager4.0.0 < 4.0.0.373affected
WSO2WSO2 API Manager4.1.0 < 4.1.0.236affected
WSO2WSO2 API Manager4.2.0 < 4.2.0.176affected
WSO2WSO2 API Manager4.3.0 < 4.3.0.88affected
WSO2WSO2 API Manager4.4.0 < 4.4.0.52affected
WSO2WSO2 API Manager4.5.0 < 4.5.0.35affected
WSO2WSO2 API Manager4.6.0 < 4.6.0.1affected
WSO2WSO2 Identity Server as Key Manager0 < 5.10.0unknown
WSO2WSO2 Identity Server as Key Manager5.10.0 < 5.10.0.369affected
WSO2WSO2 Identity Server0 < 5.10.0unknown
WSO2WSO2 Identity Server5.10.0 < 5.10.0.378affected
WSO2WSO2 Identity Server5.11.0 < 5.11.0.425affected
WSO2WSO2 Identity Server6.0.0 < 6.0.0.252affected
WSO2WSO2 Identity Server6.1.0 < 6.1.0.253affected
WSO2WSO2 Identity Server7.0.0 < 7.0.0.130affected
WSO2WSO2 Identity Server7.1.0 < 7.1.0.38affected
WSO2WSO2 Identity Server7.2.0 < 7.2.0.1affected

Weaknesses

  • CWE-78: CWE-78: Improper Neutralization of Special Elements Used in an OS Command ('OS Command Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References