CVE-2025-23171
Versa Director vulnerability analysis and mitigation

Overview

CVE-2025-23171 is an unrestricted file upload vulnerability in the Versa Director SD-WAN orchestration platform that allows an authenticated attacker to upload a webshell via the UCPE image upload functionality. The Versa Director fails to correctly enforce file upload restrictions — the UI appears to block uploads, but they succeed regardless — and additionally discloses the full filename (including UUID prefix) of uploaded temporary files, aiding exploitation. Affected versions include Versa Director 21.2.2, 21.2.3, 22.1.1, 22.1.2, 22.1.3, and 22.1.4 and earlier. The vulnerability was published on June 18–19, 2025, and carries a CVSS v3.1 base score of 7.2 (High) (Versa Security Portal, Red Hat CVE).

Technical details

The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type): the Versa Director's UCPE image upload endpoint does not properly validate or restrict the type of files that can be uploaded, despite the UI appearing to prevent such actions. An authenticated attacker can bypass the UI-level restriction and submit a file upload request directly to the backend endpoint, successfully uploading a malicious webshell. Compounding the issue, the platform discloses the full path and UUID-prefixed filename of uploaded temporary files, allowing the attacker to determine the exact location of the uploaded webshell and subsequently access it for remote code execution. A proof-of-concept has been disclosed by third-party security researchers (Versa Security Portal, Security Online).

Impact

Successful exploitation grants an authenticated attacker the ability to upload and execute arbitrary code on the Versa Director server via a webshell, resulting in full compromise of confidentiality, integrity, and availability of the affected system. An attacker with webshell access could pivot to connected SD-WAN infrastructure, exfiltrate sensitive network configuration data, intercept traffic, or disrupt SD-WAN orchestration across the enterprise. Given that Versa Director is a central orchestration platform for SD-WAN deployments, compromise could have cascading effects on all managed network devices and branches (Versa Security Portal, GBHackers).

Exploitability

A proof-of-concept for CVE-2025-23171 has been publicly disclosed by third-party security researchers, though Versa Networks states it is not aware of any confirmed in-the-wild exploitation as of the advisory date. The vulnerability requires authentication (high privileges), which somewhat limits the attack surface, but insider threats or attackers with stolen credentials remain a realistic threat vector. The EPSS score is approximately 0.043% (low), and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (Versa Security Portal, Red Hat CVE).

Exploitation steps

  1. Authenticate: Obtain valid high-privilege credentials for the Versa Director web interface (e.g., through credential theft, phishing, or insider access).
  2. Identify the upload endpoint: Locate the UCPE image upload API endpoint on the Versa Director instance. Despite the UI appearing to restrict uploads, the backend endpoint accepts file submissions.
  3. Craft a malicious upload request: Prepare a webshell file (e.g., a JSP or PHP webshell) and submit it directly to the UCPE image upload endpoint via an HTTP request, bypassing any UI-level restrictions.
  4. Retrieve the uploaded file path: Observe the server's response, which discloses the full filename of the uploaded temporary file including its UUID prefix, revealing the exact server-side path of the webshell.
  5. Access the webshell: Navigate to the disclosed file path via the web browser or HTTP client to interact with the uploaded webshell and execute arbitrary commands on the Versa Director server.
  6. Establish persistence and pivot: Use the webshell to establish a reverse shell, create backdoor accounts, or pivot to connected SD-WAN infrastructure managed by the Director (Versa Security Portal, Security Online).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to UCPE image upload endpoints on the Versa Director; outbound connections from the Versa Director server to unknown external IPs (potential reverse shell activity).
  • File System: Presence of unexpected script files (e.g., .jsp, .php, .py, .sh) in Versa Director temporary upload directories or web-accessible paths; files with UUID-prefixed names in upload directories that do not correspond to legitimate UCPE images.
  • Logs: Versa Director access logs showing successful file upload responses (HTTP 200) to upload endpoints from authenticated sessions, followed by subsequent GET requests to the same file paths; server-side error logs referencing unexpected file types in upload handling.
  • Process: Unusual child processes spawned by the Versa Director application server (e.g., bash, sh, curl, wget, python) that are not part of normal operation.

Mitigation and workarounds

Versa Networks recommends upgrading Versa Director to a remediated software version as the only effective fix; there are no configuration-based workarounds to disable the vulnerable GUI option. Patched releases include versions 22.1.2, 22.1.3, and 22.1.4 (and later), as well as 21.2.3 — organizations should verify they are running a version that includes the fix per the release notes. As interim risk reduction, restrict access to the Versa Director management interface to trusted IP ranges only, enforce strong credential hygiene, and monitor upload endpoints for anomalous activity (Versa Security Portal, Versa Release 22.1.4).

Community reactions

Security news outlets including GBHackers, SecurityOnline, CyberPress, and IT Security News covered the vulnerability shortly after disclosure, highlighting the webshell upload risk and the companion vulnerability CVE-2025-23172 (arbitrary command execution) as a pair of critical flaws in Versa Director. Community discussion on Bluesky and security aggregators noted the significance of the PoC disclosure for an SD-WAN orchestration platform with broad enterprise deployment. A Medium post by a cybersecurity awareness author framed the vulnerabilities as a critical moment for enterprises relying on Versa SD-WAN infrastructure (GBHackers, Security Online).

Additional resources


SourceThis report was generated using AI

Related Versa Director vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-24288CRITICAL9.8
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoYesJun 19, 2025
CVE-2025-23173HIGH7.5
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025
CVE-2025-23172HIGH7.2
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025
CVE-2025-23171HIGH7.2
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025
CVE-2025-24291MEDIUM6.1
  • Versa Director logoVersa Director
  • cpe:2.3:a:versa-networks:versa_director
NoNoJun 19, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management