CVE-2025-13590: Authenticated arbitrary file upload via a System REST API requiring administrator permission.
A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution.
By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.wso2.carbon.apimgt:org.wso2.carbon.apimgt.implto a version that resolves this vulnerability.Fixed in 9.32.167
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13590?
CVE-2025-13590 is classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2025-13590?
To fix CVE-2025-13590, upgrade affected systems to the recommended version of the WSO2 APIs, specifically to versions above 9.32.167.
Which software versions are affected by CVE-2025-13590?
CVE-2025-13590 affects specific versions of WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway, specifically versions 4.2.0 to 4.6.0.
Can CVE-2025-13590 be exploited by non-administrative users?
No, CVE-2025-13590 requires administrative privileges for exploitation, making it critical to restrict access to administrative accounts.
What are the potential consequences of exploiting CVE-2025-13590?
Exploiting CVE-2025-13590 can lead to unauthorized file uploads, potentially enabling remote code execution on affected systems.