Remote Code Execution Risk in Versa Director SD-WAN Orchestration Platform
CVE-2025-23173
What is CVE-2025-23173?
The Versa Director SD-WAN orchestration platform faces a significant vulnerability due to its websockify service being exposed on port 6080 by default. This exposure allows for remote access to uCPE virtual machines via the Director GUI, posing a serious risk as websockify is vulnerable to known attacks that could potentially lead to remote code execution. Although there have been no recorded instances of this flaw being exploited, security researchers have released proof of concept code to demonstrate its potential impact. Users of the platform are advised to restrict access to port 6080 if console access is not required and to upgrade to the latest remediated software versions to mitigate risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Director 21.2.2
Director 21.2.3
Director 22.1.1
References
CVSS V3.1
Timeline
Vulnerability published
