PT-2025-26193 · Versa · Versa Director Sd-Wan Orchestration Platform

Published

2025-06-18

·

Updated

2025-07-26

·

CVE-2025-23171

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Versa Director SD-WAN orchestration platform (affected versions not specified)
Description The Versa Director SD-WAN orchestration platform has an issue with file upload permissions, allowing authenticated attackers to upload arbitrary files, including webshells, despite the UI not appearing to allow file uploads. Additionally, the platform discloses the full filename of uploaded temporary files. There are no reported instances of this issue being exploited, but a proof of concept has been disclosed by third-party security researchers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Privilege Assignment

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2025-09777
CVE-2025-23171

Affected Products

Versa Director Sd-Wan Orchestration Platform