---
id: CVE-2025-34027
title: >-
  The Versa Concerto SD-WAN orchestration platform is vulnerable to an
  authentication bypass in the Traefik reverse proxy configuration, allowing at
  attacker to access administrative endpoints
summary: >-
  The Versa Concerto SD-WAN orchestration platform is vulnerable to an
  authentication bypass in the Traefik reverse proxy configuration, allowing at
  attacker to access administrative endpoints. The Spack upload endpoint can be
  leveraged fo…
severity: none
cwe:
  - CWE-367
published: '2025-05-21'
updated: '2026-08-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34027'
references:
  - url: 'https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce'
    label: disclosure@vulncheck.com
  - url: 'https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
epss: 0.4522
epssPercentile: 0.98768
ingestedAt: '2026-08-24T21:11:23.787Z'
exploits:
  nuclei:
    - CVE-2025-34027
  checkedAt: '2026-09-21T15:27:21.240Z'
exploitAvailable: true
---

## Overview

The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The Spack upload endpoint can be leveraged for a Time-of-Check to Time-of-Use (TOCTOU) write in combination with a race condition to achieve remote code execution via path loading manipulation, allowing an unauthenticated actor to achieve remote code execution (RCE).This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
