PT-2025-26194 · Versa · Versa Director

Published

2025-06-18

·

Updated

2025-07-26

·

CVE-2025-23172

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Versa Director SD-WAN orchestration platform (affected versions not specified)
Description The Versa Director SD-WAN orchestration platform has a Webhook feature that can be abused by an authenticated user to send crafted HTTP requests to localhost, potentially leading to privilege escalation or remote code execution. The "Add Webhook" and "Test Webhook" functionalities can be exploited to execute commands on behalf of the versa user, who has sudo privileges. There are no reported instances of this vulnerability being exploited, but a proof of concept has been disclosed by third-party security researchers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

RCE

Improper Access Control

SSRF

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-09776
CVE-2025-23172

Affected Products

Versa Director