PT-2025-26197 · Versa · Versa Director Sd-Wan Orchestration Platform

Published

2025-06-18

·

Updated

2025-06-19

·

CVE-2025-24291

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Versa Director SD-WAN orchestration platform (affected versions not specified)
Description The issue concerns the Java code handling file uploads in the Versa Director SD-WAN orchestration platform, which contains an argument injection vulnerability. This allows an attacker to bypass MIME type validation by appending additional arguments to the file name, enabling the upload of arbitrary file types. As a result, a malicious file can be placed on disk. There are no reported instances of this vulnerability being exploited, but a proof of concept has been disclosed by third-party security researchers.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Argument Injection

Weakness Enumeration

Related Identifiers

BDU:2025-09792
CVE-2025-24291

Affected Products

Versa Director Sd-Wan Orchestration Platform