CVE-2025-3125
Authenticated Arbitrary File Upload in Multiple WSO2 Products via CarbonAppUploader Admin Service Leading to Remote Code Execution
Record summary
CVE-2025-3125 has a selected CVSS score of 6.7 (medium).
Description
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with appropriate privileges can upload a malicious file to a user-controlled location on the server, potentially leading to remote code execution (RCE). This functionality is restricted by default to admin users; therefore, successful exploitation requires valid credentials with administrative permissions.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 5, 2025 · Source: CVE List
Affected products and versions
9| Product | Source | Version range | Status |
|---|---|---|---|
WSO2 API Control PlaneBrowse WSO2 / WSO2 API Control PlaneDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.2 | affected |
| 4.6.0 to < 4.6.0.3 | affected | ||
WSO2 API ManagerBrowse WSO2 / WSO2 API ManagerDefault status: unaffected | CVE List | Before 3.2.0 | unknown |
| 3.2.0 to < 3.2.0.421 | affected | ||
| 3.2.1 to < 3.2.1.41 | affected | ||
| 4.0.0 to < 4.0.0.342 | affected | ||
| 4.1.0 to < 4.1.0.203 | affected | ||
| 4.2.0 to < 4.2.0.142 | affected | ||
| 4.3.0 to < 4.3.0.55 | affected | ||
| 4.4.0 to < 4.4.0.19 | affected | ||
| 4.5.0 to < 4.5.0.2 | affected | ||
| 4.6.0 to < 4.6.0.3 | affected | ||
WSO2 Enterprise IntegratorBrowse WSO2 / WSO2 Enterprise IntegratorDefault status: unaffected | CVE List | Before 6.6.0 | unknown |
| 6.6.0 to < 6.6.0.217 | affected | ||
WSO2 Identity ServerBrowse WSO2 / WSO2 Identity ServerDefault status: unaffected | CVE List | Before 5.10.0 | unknown |
| 5.10.0 to < 5.10.0.360 | affected | ||
| 5.11.0 to < 5.11.0.399 | affected | ||
| 6.0.0 to < 6.0.0.235 | affected | ||
| 6.1.0 to < 6.1.0.230 | affected | ||
| 7.0.0 to < 7.0.0.101 | affected | ||
| 7.1.0 to < 7.1.0.32 | affected | ||
WSO2 Identity Server as Key ManagerBrowse WSO2 / WSO2 Identity Server as Key ManagerDefault status: unaffected | CVE List | Before 5.10.0 | unknown |
| 5.10.0 to < 5.10.0.353 | affected | ||
WSO2 Open Banking IAMBrowse WSO2 / WSO2 Open Banking IAMDefault status: unaffected | CVE List | Before 2.0.0 | unknown |
| 2.0.0 to < 2.0.0.402 | affected | ||
WSO2 Traffic ManagerBrowse WSO2 / WSO2 Traffic ManagerDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.2 | affected |
| 4.6.0 to < 4.6.0.3 | affected | ||
WSO2 Universal GatewayBrowse WSO2 / WSO2 Universal GatewayDefault status: unaffected | CVE List | 4.5.0 to < 4.5.0.2 | affected |
| 4.6.0 to < 4.6.0.3 | affected | ||
org.wso2.carbon.commons:org.wso2.carbon.application.uploadBrowse WSO2 / org.wso2.carbon.commons:org.wso2.carbon.application.uploadDefault status: unknown | CVE List | 4.7.19 to < 4.7.19.7 | affected |
| 4.7.32 to < 4.7.32.5 | affected | ||
| 4.7.35 to < 4.7.35.8 | affected | ||
| 4.7.39 to < 4.7.39.1 | affected | ||
| 4.7.49 to < 4.7.49.4 | affected | ||
| 4.7.52 to < 4.7.52.1 | affected | ||
| 4.10.13 to < 4.10.13.1 | affected | ||
| 4.9.12 to ≤ 4.9.* | unaffected | ||
| 4.10.24 to ≤ * | unaffected |