← All CVEs

CVE-2025-13590

critical · 9.1

A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially crafted payload.

9.1
CVSS
0.7%
EPSS (exploit prob.)
52nd
EPSS percentile
2026-02-19
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-434

Affected products

VendorProductAffected versions
wso2api_control_plane4.5.0
wso2api_control_plane4.6.0
wso2api_manager4.2.0
wso2api_manager4.3.0
wso2api_manager4.4.0
wso2api_manager4.5.0
wso2api_manager4.6.0
wso2traffic_manager4.5.0
wso2traffic_manager4.6.0
wso2universal_gateway4.5.0
wso2universal_gateway4.6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-13590