Argument Injection Vulnerability in Versa Director SD-WAN Orchestration Platform
CVE-2025-24291

6.1MEDIUM

Key Information:

Vendor

Versa

Status
Vendor
CVE Published:
19 June 2025

What is CVE-2025-24291?

The Versa Director SD-WAN orchestration platform has a vulnerability in its file upload functionality due to improper handling of arguments in uploaded filenames. This flaw allows attackers to bypass MIME type validation, enabling them to upload arbitrary file types, potentially facilitating the placement of malicious files on disk. Although no exploitation has been reported, the existence of a proof of concept from security researchers highlights the importance of addressing this issue. Users are advised to upgrade to the remediated software versions as there are no available workarounds to disable the affected GUI options.

Affected Version(s)

Director 21.2.2

Director 21.2.3

Director 22.1.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.