NA - CVE-2025-23168 - The Versa Director SD-WAN orchestration...
The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input...
NA - CVE-2025-23169 - The Versa Director SD-WAN orchestration...
The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not...
NA - CVE-2025-23170 - The Versa Director SD-WAN orchestration...
The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script,...
NA - CVE-2025-23171 - The Versa Director SD-WAN orchestration...
The Versa Director SD-WAN orchestration platform provides an option to upload various types of files. The Versa Director does not correctly limit file upload permissions. The UI appears not to...
NA - CVE-2025-23172 - The Versa Director SD-WAN orchestration...
The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can...
NA - CVE-2025-23173 - The Versa Director SD-WAN orchestration...
The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and...
NA - CVE-2025-24287 - A vulnerability allowing local system users to...
A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions.
NA - CVE-2025-24288 - The Versa Director software exposes a number of...
The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the...
NA - CVE-2025-24291 - The Versa Director SD-WAN orchestration...
The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability....