CVE-2025-12737

EUVD-2025-210842
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely.

Successful exploitation enables a threat actor with administrative privileges and Carbon Console access to execute remote arbitrary code through specific administrative operations, leading to a complete compromise of the affected system.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
WSO2CNA
8.4 HIGH
ADJACENT_NETWORK
LOW
HIGH
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
wso2open_banking_am
2.0.0 ≤
𝑥
< 2.0.0.398
CNA
wso2open_banking_am
2.0.0 ≤
𝑥
< 2.0.0.418
CNA
wso2open_banking_am
4.5.0 ≤
𝑥
< 4.5.0.34
CNA
wso2open_banking_am
4.6.0 ≤
𝑥
< 4.6.0.1
CNA
wso2open_banking_am
4.5.0 ≤
𝑥
< 4.5.0.36
CNA
wso2open_banking_am
3.1.0 ≤
𝑥
< 3.1.0.349
CNA
wso2open_banking_am
3.2.0 ≤
𝑥
< 3.2.0.453
CNA
wso2open_banking_am
3.2.1 ≤
𝑥
< 3.2.1.73
CNA
wso2open_banking_am
4.0.0 ≤
𝑥
< 4.0.0.373
CNA
wso2open_banking_am
4.1.0 ≤
𝑥
< 4.1.0.236
CNA
wso2open_banking_am
4.2.0 ≤
𝑥
< 4.2.0.176
CNA
wso2open_banking_am
4.3.0 ≤
𝑥
< 4.3.0.88
CNA
wso2open_banking_am
4.4.0 ≤
𝑥
< 4.4.0.52
CNA
wso2open_banking_am
4.5.0 ≤
𝑥
< 4.5.0.35
CNA
wso2open_banking_am
5.10.0 ≤
𝑥
< 5.10.0.369
CNA
wso2open_banking_am
5.10.0 ≤
𝑥
< 5.10.0.378
CNA
wso2open_banking_am
5.11.0 ≤
𝑥
< 5.11.0.425
CNA
wso2open_banking_am
6.0.0 ≤
𝑥
< 6.0.0.252
CNA
wso2open_banking_am
6.1.0 ≤
𝑥
< 6.1.0.253
CNA
wso2open_banking_am
7.0.0 ≤
𝑥
< 7.0.0.130
CNA
wso2open_banking_am
7.1.0 ≤
𝑥
< 7.1.0.38
CNA
wso2open_banking_am
7.2.0 ≤
𝑥
< 7.2.0.1
CNA