BR100 Increased By (0.36%)
BR30 Decreased By (-0.13%)
KSE100 Increased By (0.22%)
KSE30 Increased By (0.37%)
AGHA 6.68 Increased By ▲ 0.01 (0.15%)
BECO 4.37 No Change ▼ 0.00 (0%)
BML 57.32 Increased By ▲ 0.88 (1.56%)
BOP 30.35 Increased By ▲ 0.01 (0.03%)
CNERGY 13.12 Increased By ▲ 0.03 (0.23%)
CSIL 5.41 Increased By ▲ 0.05 (0.93%)
FCCL 52.79 Increased By ▲ 0.41 (0.78%)
FFL 14.72 Decreased By ▼ -0.02 (-0.14%)
FNEL 1.12 No Change ▼ 0.00 (0%)
KEL 6.09 No Change ▼ 0.00 (0%)
KOSM 5.73 Increased By ▲ 0.77 (15.52%)
LOTCHEM 26.46 Decreased By ▼ -0.89 (-3.25%)
MLCF 93.16 Increased By ▲ 0.41 (0.44%)
NBP 164.66 Decreased By ▼ -0.32 (-0.19%)
NCPL 55.66 Increased By ▲ 0.02 (0.04%)
NPL 61.16 Decreased By ▼ -0.10 (-0.16%)
OGDC 316.73 Decreased By ▼ -1.03 (-0.32%)
PACE 9.87 Decreased By ▼ -0.06 (-0.6%)
PAEL 35.63 Increased By ▲ 0.13 (0.37%)
PIBTL 14.68 Increased By ▲ 0.11 (0.75%)
PPL 226.91 Decreased By ▼ -0.88 (-0.39%)
PRL 93.02 Increased By ▲ 0.45 (0.49%)
PTC 60.26 Decreased By ▼ -0.37 (-0.61%)
SSGC 23.81 Increased By ▲ 0.01 (0.04%)
TBL 8.75 Increased By ▲ 0.07 (0.81%)
TELE 7.80 Increased By ▲ 0.02 (0.26%)
TPL 22.35 Increased By ▲ 0.12 (0.54%)
TPLP 12.97 Increased By ▲ 0.30 (2.37%)
TREET 22.16 Decreased By ▼ -0.38 (-1.69%)
TRG 56.56 Decreased By ▼ -1.24 (-2.15%)

ISLAMABAD: The National Computer Emergency Response Team (NCERT) has issued a high-priority advisory warning to businesses of a critical vulnerability in Adobe Commerce and Magento Open Source platforms, dubbed SessionReaper.

The flaw, tracked as CVE-2025-54236, has been rated at CVSS 9.1 (Critical) and arises from improper input validation in the Commerce REST API. Successful exploitation could allow attackers to hijack customer sessions, gain unauthorized access to accounts, and, under certain conditions, execute remote code on affected servers.

According to NCERT, the vulnerability impacts multiple deployment methods of Adobe Commerce, Magento Open Source, B2B extensions, and the Custom Attributes Serializable Module. It poses a high risk of customer data theft, hijacked transactions, and potential full system compromise.

National CERT issues urgent data protection alert

If exploited, attackers could achieve: Account takeover and theft of sensitive customer information, remote code execution (RCE) in environments with file-based session storage enabled, privilege escalation through stolen tokens or API keys, and service disruption, potentially leading to widespread downtime of eCommerce operations.

NCERT has urged organizations to apply emergency hotfix VULN-32437-2-4-X-patch or upgrade to the latest Adobe release (APSB25-88) without delay. It also recommended rotating administrator and API credentials immediately, restricting REST API exposure to trusted networks, enforcing strict WAF/IDS/IPS rules to detect and block malicious traffic, the monitoring logs for abnormal login attempts, session manipulation, and privilege escalations.

The advisory warned that large-scale exploitation campaigns could emerge quickly, given the low complexity of attacks and the absence of authentication requirements.

“Timely patching is essential to prevent mass compromise of eCommerce platforms,” NCERT said, urging businesses to strengthen monitoring and apply defense-in-depth measures.

Copyright Business Recorder, 2025

Comments

Comments are closed for this article.