versa-networks has 5 CVEs on record between 2021 and 2025. The median CVSS is 7.8 (high), with 2 rated critical. None have a confirmed exploitation report. Most affected products: versa_director (4), versa_analytics (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Weakness classes
Products
- versa_director 4
- versa_analytics 1
Worst active — by depth score
CVE-2025-24288Critical· 9.8The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials54CVE-2019-25029Critical· 9.8In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application54CVE-2018-16497High· 7.8In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server43CVE-2025-23173High· 7.5The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI41CVE-2025-24291Medium· 6.1The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files34
versa-networks vulnerabilities
CVEs affecting versa-networks, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2025-24291Medium· 6.1The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files
The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the…
CVE-2025-23173High· 7.5The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI
The Versa Director SD-WAN orchestration platform provides direct web-based access to uCPE virtual machines through the Director GUI. By default, the websockify service is exposed on port 6080 and accessible from the internet. This exposu…
CVE-2025-24288Critical· 9.8The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials
The Versa Director software exposes a number of services by default and allow attackers an easy foothold due to default credentials and multiple accounts (most with sudo access) that utilize the same default credentials. By default, Vers…
CVE-2019-25029Critical· 9.8In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application
In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsaf…
CVE-2018-16497High· 7.8In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server
In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a potential privilege escalation vulnerability. In this case, t…