Goal Reached Thanks to every supporter β€” we hit 100%!

Goal: 1000 CNY Β· Raised: 1000 CNY

100.0%

CVE-2025-13590 β€” AI Deep Analysis Summary

CVSS 9.1 Β· Critical

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: WSO2 products suffer from an **Arbitrary File Upload** flaw via REST API.…

Q2Root Cause? (CWE/Flaw)

πŸ›‘οΈ **Root Cause**: The vulnerability stems from insufficient validation in the **REST API** endpoints.…

Q3Who is affected? (Versions/Components)

πŸ“¦ **Affected Products**: <br>β€’ **WSO2 API Manager** <br>β€’ **WSO2 API Control Plane** <br>β€’ **WSO2 Traffic Manager** <br>*(Note: Data indicates 'multiple products' but specifically lists these three).*

Q4What can hackers do? (Privileges/Data)

πŸ’€ **Attacker Capabilities**: <br>β€’ Upload **arbitrary files** (e.g., webshells, scripts). <br>β€’ Achieve **Remote Code Execution (RCE)**. <br>β€’ Gain full control over the affected server components.…

Q5Is exploitation threshold high? (Auth/Config)

πŸ”’ **Exploitation Threshold**: <br>β€’ **Auth Required**: YES. Requires **High Privileges** (Administrative access). <br>β€’ **CVSS Vector**: `PR:H` (Privileges Required: High).…

Q6Is there a public Exp? (PoC/Wild Exploitation)

πŸ•΅οΈ **Public Exploit**: <br>β€’ **PoC Status**: **None** listed in the provided data (`pocs: []`). <br>β€’ **Wild Exploitation**: Unconfirmed based on current data.…

Q7How to self-check? (Features/Scanning)

πŸ” **Self-Check Method**: <br>1. Identify if you run **WSO2 API Manager** or **Control Plane**. <br>2. Check for exposed **REST API** endpoints with admin privileges. <br>3.…

Q8Is it fixed officially? (Patch/Mitigation)

🩹 **Official Fix**: <br>β€’ **Status**: A vendor advisory was published on **2026-02-19**.…

Q9What if no patch? (Workaround)

πŸ›‘ **No Patch Workaround**: <br>1. **Restrict Access**: Block external access to WSO2 REST API endpoints. <br>2. **Least Privilege**: Ensure only trusted admins have API access. <br>3.…

Q10Is it urgent? (Priority Suggestion)

⚑ **Urgency**: **HIGH** <br>β€’ **CVSS Score**: **9.1** (Critical). <br>β€’ **Impact**: Full system compromise (Confidentiality, Integrity, Availability all High).…