Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-13590 — AI Deep Analysis Summary

CVSS 9.1 · Critical

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: WSO2 products suffer from an **Arbitrary File Upload** flaw via REST API.…

Q2Root Cause? (CWE/Flaw)

🛡️ **Root Cause**: The vulnerability stems from insufficient validation in the **REST API** endpoints.…

Q3Who is affected? (Versions/Components)

📦 **Affected Products**: <br>• **WSO2 API Manager** <br>• **WSO2 API Control Plane** <br>• **WSO2 Traffic Manager** <br>*(Note: Data indicates 'multiple products' but specifically lists these three).*

Q4What can hackers do? (Privileges/Data)

💀 **Attacker Capabilities**: <br>• Upload **arbitrary files** (e.g., webshells, scripts). <br>• Achieve **Remote Code Execution (RCE)**. <br>• Gain full control over the affected server components.…

Q5Is exploitation threshold high? (Auth/Config)

🔒 **Exploitation Threshold**: <br>• **Auth Required**: YES. Requires **High Privileges** (Administrative access). <br>• **CVSS Vector**: `PR:H` (Privileges Required: High).…

Q6Is there a public Exp? (PoC/Wild Exploitation)

🕵️ **Public Exploit**: <br>• **PoC Status**: **None** listed in the provided data (`pocs: []`). <br>• **Wild Exploitation**: Unconfirmed based on current data.…

Q7How to self-check? (Features/Scanning)

🔍 **Self-Check Method**: <br>1. Identify if you run **WSO2 API Manager** or **Control Plane**. <br>2. Check for exposed **REST API** endpoints with admin privileges. <br>3.…

Q8Is it fixed officially? (Patch/Mitigation)

🩹 **Official Fix**: <br>• **Status**: A vendor advisory was published on **2026-02-19**.…

Q9What if no patch? (Workaround)

🛑 **No Patch Workaround**: <br>1. **Restrict Access**: Block external access to WSO2 REST API endpoints. <br>2. **Least Privilege**: Ensure only trusted admins have API access. <br>3.…

Q10Is it urgent? (Priority Suggestion)

⚡ **Urgency**: **HIGH** <br>• **CVSS Score**: **9.1** (Critical). <br>• **Impact**: Full system compromise (Confidentiality, Integrity, Availability all High).…