
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-23171 is an unrestricted file upload vulnerability in the Versa Director SD-WAN orchestration platform that allows an authenticated attacker to upload a webshell via the UCPE image upload functionality. The Versa Director fails to correctly enforce file upload restrictions — the UI appears to block uploads, but they succeed regardless — and additionally discloses the full filename (including UUID prefix) of uploaded temporary files, aiding exploitation. Affected versions include Versa Director 21.2.2, 21.2.3, 22.1.1, 22.1.2, 22.1.3, and 22.1.4 and earlier. The vulnerability was published on June 18–19, 2025, and carries a CVSS v3.1 base score of 7.2 (High) (Versa Security Portal, Red Hat CVE).
The root cause is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type): the Versa Director's UCPE image upload endpoint does not properly validate or restrict the type of files that can be uploaded, despite the UI appearing to prevent such actions. An authenticated attacker can bypass the UI-level restriction and submit a file upload request directly to the backend endpoint, successfully uploading a malicious webshell. Compounding the issue, the platform discloses the full path and UUID-prefixed filename of uploaded temporary files, allowing the attacker to determine the exact location of the uploaded webshell and subsequently access it for remote code execution. A proof-of-concept has been disclosed by third-party security researchers (Versa Security Portal, Security Online).
Successful exploitation grants an authenticated attacker the ability to upload and execute arbitrary code on the Versa Director server via a webshell, resulting in full compromise of confidentiality, integrity, and availability of the affected system. An attacker with webshell access could pivot to connected SD-WAN infrastructure, exfiltrate sensitive network configuration data, intercept traffic, or disrupt SD-WAN orchestration across the enterprise. Given that Versa Director is a central orchestration platform for SD-WAN deployments, compromise could have cascading effects on all managed network devices and branches (Versa Security Portal, GBHackers).
A proof-of-concept for CVE-2025-23171 has been publicly disclosed by third-party security researchers, though Versa Networks states it is not aware of any confirmed in-the-wild exploitation as of the advisory date. The vulnerability requires authentication (high privileges), which somewhat limits the attack surface, but insider threats or attackers with stolen credentials remain a realistic threat vector. The EPSS score is approximately 0.043% (low), and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (Versa Security Portal, Red Hat CVE).
.jsp, .php, .py, .sh) in Versa Director temporary upload directories or web-accessible paths; files with UUID-prefixed names in upload directories that do not correspond to legitimate UCPE images.bash, sh, curl, wget, python) that are not part of normal operation.Versa Networks recommends upgrading Versa Director to a remediated software version as the only effective fix; there are no configuration-based workarounds to disable the vulnerable GUI option. Patched releases include versions 22.1.2, 22.1.3, and 22.1.4 (and later), as well as 21.2.3 — organizations should verify they are running a version that includes the fix per the release notes. As interim risk reduction, restrict access to the Versa Director management interface to trusted IP ranges only, enforce strong credential hygiene, and monitor upload endpoints for anomalous activity (Versa Security Portal, Versa Release 22.1.4).
Security news outlets including GBHackers, SecurityOnline, CyberPress, and IT Security News covered the vulnerability shortly after disclosure, highlighting the webshell upload risk and the companion vulnerability CVE-2025-23172 (arbitrary command execution) as a pair of critical flaws in Versa Director. Community discussion on Bluesky and security aggregators noted the significance of the PoC disclosure for an SD-WAN orchestration platform with broad enterprise deployment. A Medium post by a cybersecurity awareness author framed the vulnerabilities as a critical moment for enterprises relying on Versa SD-WAN infrastructure (GBHackers, Security Online).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."