Argument Injection Vulnerability in Versa Director SD-WAN Orchestration Platform
CVE-2025-24291
What is CVE-2025-24291?
The Versa Director SD-WAN orchestration platform has a vulnerability in its file upload functionality due to improper handling of arguments in uploaded filenames. This flaw allows attackers to bypass MIME type validation, enabling them to upload arbitrary file types, potentially facilitating the placement of malicious files on disk. Although no exploitation has been reported, the existence of a proof of concept from security researchers highlights the importance of addressing this issue. Users are advised to upgrade to the remediated software versions as there are no available workarounds to disable the affected GUI options.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Director 21.2.2
Director 21.2.3
Director 22.1.1
References
CVSS V3.1
Timeline
Vulnerability published
