Remote Code Execution Vulnerability in Carbon Console by WSO2
CVE-2025-12737

8.4HIGH

What is CVE-2025-12737?

A vulnerability exists within the Carbon Console due to inadequate input validation in administrative operations. This flaw enables an attacker with existing administrative privileges to inject and execute arbitrary code remotely. The exploitation of this vulnerability allows complete compromise of the system, emphasizing the importance of strict input validation mechanisms in safeguarding against such security threats.

Affected Version(s)

WSO2 API Control Plane 4.5.0 < 4.5.0.36

WSO2 API Control Plane 4.6.0 < 4.6.0.1

WSO2 API Manager 3.1.0 < 3.1.0.349

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.