CVE-2025-3125
Last modified
CVE-2025-3125 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with appropriate privileges can upload a malicious file to a user-controlled location on the server, potentially leading to remote code execution (RCE). This functionality is restricted by default to admin users; therefore, successful exploitation requires valid credentials with administrative permissions.. EPSS estimates a 0.76% chance of exploitation in the next 30 days.
Description
An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker with appropriate privileges can upload a malicious file to a user-controlled location on the server, potentially leading to remote code execution (RCE). This functionality is restricted by default to admin users; therefore, successful exploitation requires valid credentials with administrative permissions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Api Control Plane | 4.5.0 |
| Wso2 | Api Manager | 3.2.0 |
| Wso2 | Api Manager | 3.2.1 |
| Wso2 | Api Manager | 4.0.0 |
| Wso2 | Api Manager | 4.1.0 |
| Wso2 | Api Manager | 4.2.0 |
| Wso2 | Api Manager | 4.3.0 |
| Wso2 | Api Manager | 4.4.0 |
| Wso2 | Api Manager | 4.5.0 |
| Wso2 | Enterprise Integrator | 6.6.0 |
| Wso2 | Identity Server | 5.10.0 |
| Wso2 | Identity Server | 5.11.0 |
| Wso2 | Identity Server | 6.0.0 |
| Wso2 | Identity Server | 6.1.0 |
| Wso2 | Identity Server | 7.0.0 |
| Wso2 | Identity Server As Key Manager | 5.10.0 |
| Wso2 | Open Banking Iam | 2.0.0 |
| Wso2 | Traffic Manager | 4.5.0 |
| Wso2 | Universal Gateway | 4.5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-3125?
How severe is CVE-2025-3125?
How do I fix CVE-2025-3125?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-31244A file quarantine bypass was addressed with additional check…8.8
- CVE-2025-31245The issue was addressed with improved checks. This issue is …5.5
- CVE-2025-31246The issue was addressed with improved memory handling. This …8.8
- CVE-2025-31247A logic issue was addressed with improved state management. …7.5
- CVE-2025-31248A parsing issue in the handling of directory paths was addre…5.5
- CVE-2025-31249A logic issue was addressed with improved checks. This issue…7.1
- CVE-2025-31250An information disclosure issue was addressed with improved …5.5
- CVE-2025-31251The issue was addressed with improved input sanitization. Th…5.5
- CVE-2025-31253This issue was addressed through improved state management. …7.1
- CVE-2025-31254This issue was addressed with improved URL validation. This …5.4
- CVE-2025-31255An authorization issue was addressed with improved state man…9.8
- CVE-2025-31256The issue was addressed with improved handling of caches. Th…5.5
Are you affected by CVE-2025-3125?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
