
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-24291 is an argument injection vulnerability in the Versa Director SD-WAN orchestration platform's Java-based file upload functionality. By appending additional arguments to a filename, an authenticated attacker can bypass MIME type validation and upload arbitrary file types, potentially placing malicious files on disk. The vulnerability was disclosed on June 18–19, 2025, and was reported via HackerOne. Affected versions include Versa Director 21.2.2, 21.2.3, 22.1.1, 22.1.2, 22.1.3, and 22.1.4. It carries a CVSS v3.1 base score of 6.1 (Medium), though exploitation requires high privileges and user interaction (Versa Security Portal, EUVD).
The root cause is classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — Injection), with an estimated secondary classification of CWE-434 (Unrestricted Upload of File with Dangerous Type). The Java code responsible for handling file uploads fails to properly sanitize the filename parameter; an attacker can inject additional command-line arguments into the filename string, causing the underlying file-handling logic to bypass MIME type checks. This allows files of arbitrary types — including potentially executable scripts or web shells — to be written to disk on the Director host. Exploitation requires network access, high privileges (authenticated user), and user interaction, limiting the attack surface somewhat (Versa Security Portal, EUVD).
Successful exploitation allows an attacker to place arbitrary files — including malicious scripts or web shells — on the Versa Director host filesystem, resulting in high confidentiality and integrity impact. An attacker who achieves file placement could potentially escalate to remote code execution, access sensitive SD-WAN configuration data, or pivot to managed network devices. Availability is not directly impacted by this vulnerability alone, but secondary exploitation of uploaded malicious files could extend the impact significantly (Versa Security Portal, EUVD).
Versa Networks has stated it is not aware of any reported instances of active exploitation in the wild. However, a proof-of-concept (PoC) has been publicly disclosed by third-party security researchers, raising the risk of future exploitation. The EPSS score is approximately 0.029% (very low), and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated user with high privileges and user interaction, which constrains the immediate threat level (Versa Security Portal, EUVD).
malicious.jsp --bypass-mime-check..jsp, .sh) to be written to disk..jsp, .sh, .py, .php) in Director upload or web-accessible directories; newly created files with suspicious names or timestamps in application directories.--, -, flags); Java exceptions or errors related to MIME type processing during upload operations.curl or wget) following a file upload event.Versa Networks recommends upgrading Versa Director to a remediated software version as the only effective fix, as there are no workarounds available to disable the vulnerable GUI file upload option. Patched releases include versions 22.1.2 (patch), 22.1.3, 22.1.4, and 21.2.3 — administrators should consult the respective release notes for their upgrade path. Additionally, organizations should restrict access to the Versa Director management interface to trusted networks and enforce the principle of least privilege for Director accounts to reduce the attack surface (Versa Security Portal, Release 22.1.4, Release 21.2.3).
Versa Networks explicitly stated in its security bulletin that it is not aware of any reported exploitation of this vulnerability, and noted that a PoC was disclosed by third-party security researchers. The vulnerability was assigned via HackerOne, indicating responsible disclosure through a bug bounty program. No significant public researcher commentary or broad media coverage has been identified beyond the vendor advisory and standard vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."