CVE-2025-24291
Last modified
CVE-2025-24291 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allowing the upload of arbitrary file types. This flaw can be exploited to place a malicious file on disk. Versa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers. There are no workarounds to disable the GUI option. Versa recommends that Director be upgraded to one of the remediated software versions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-24291?
How severe is CVE-2025-24291?
How do I fix CVE-2025-24291?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-24285Multiple Improper Input Validation vulnerabilities in UniFi …9.8
- CVE-2025-24286A vulnerability allowing an authenticated user with the Back…4.9
- CVE-2025-24287A vulnerability allowing local system users to modify direct…6.1
- CVE-2025-24288The Versa Director software exposes a number of services by …9.8
- CVE-2025-24289A Cross-Site Request Forgery (CSRF) leading to Cross-Site Sc…7.5
- CVE-2025-24290Multiple Authenticated SQL Injection vulnerabilities found i…9.9
- CVE-2025-24292A misconfigured query in UniFi Network (v9.1.120 and earlier…6.8
- CVE-2025-24293# Active Storage allowed transformation methods potentially …9.2
- CVE-2025-24294The attack vector is a potential Denial of Service (DoS). Th…7.5
- CVE-2025-24296Improper input validation in some firmware for the Intel(R) …6
- CVE-2025-24297Due to lack of server-side input validation, attackers can i…9.8
- CVE-2025-24298in OpenHarmony v5.0.3 and prior versions allow a local attac…7.8
Are you affected by CVE-2025-24291?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
