CVE-2019-25029Critical· 9.8▾ MidnightIn Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsaf…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 31.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.7%
In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP headers etc.) to a system shell. In this attack, the attacker-supplied operating system commands are usually executed with the privileges of the vulnerable application. Command injection attacks are possible largely due to insufficient input validation.
versa_director < 16.1R2S11versa_director >= 20.2.0, < 20.2.2versa_director >= 21.1.0, < 21.1.1versa_director >= 21.2.0, < 21.2.1Upgrade past the affected range:
versa_director 21.2.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-23173High· 7.5The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI
CVE-2025-24291Medium· 6.1The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files
CVE-2025-24288Critical· 9.8The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials
CVE-2025-13799Medium· 6.3A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c
CVE-2025-13797Medium· 6.3A vulnerability was detected in ADSLR B-QE2W401 250814-r037c
CVE-2018-19949Critical· 9.8If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands