CVE-2025-23170

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
19/06/2025
Last modified:
23/06/2025

Description

The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the user argument. This allows an attacker to execute arbitrary commands on the system. <br /> <br /> Exploitation Status: <br /> <br /> Versa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers. <br /> <br /> Workarounds or Mitigation: <br /> <br /> There are no workarounds to disable the GUI option. Versa recommends that Director be upgraded to one of the remediated software versions.