Significant vulnerabilities were uncovered in Versa Concerto, a widely deployed SD-WAN orchestration platform used by major enterprises and government entities.
The flaws include authentication bypass vulnerabilities that can be chained to achieve remote code execution and complete system compromise.
Despite responsible disclosure efforts beginning in February 2025, these critical issues remain unpatched, leaving organizations vulnerable to attack.
The Versa Concerto platform, which provides network security and SD-WAN orchestration capabilities, contains a severe Time-of-Check to Time-of-Use (TOCTOU) vulnerability in its authentication mechanism.
The flaw stems from inconsistent URL processing between the authentication check and controller handling.
“During the authentication check, the REQUEST_URI undergoes URL decoding. However, the URL is processed without decoding to the controllers,” ProjectDiscovery researchers shared with Cyber Security News.
This inconsistency allows attackers to craft special URLs that bypass authentication controls.
The exploit leverages semicolons and URL-encoded slashes in requests. For example, sending a request to /portalapi/v1/users/username/admin;%2fv1%2fping causes the authentication filter to misidentify it as an excluded endpoint.
Organizations using Versa Concerto for their network infrastructure management are at significant risk, as these vulnerabilities have been assigned a CVSS score of 10.0, indicating critical severity.
Once authentication is bypassed, attackers can exploit an arbitrary file write vulnerability in the /portalapi/v1/package/spack/upload endpoint.
Although exception handlers quickly delete uploaded files, researchers demonstrated a race condition that allows for successful exploitation.
The attack chain involves:
Additional vulnerabilities include a Spring Boot Actuator authentication bypass (CVE-2025-34026) that can be triggered with this HTTP request:
This exploit leverages a vulnerability in Traefik (CVE-2024-45410) that allows manipulation of HTTP headers.
The researchers followed responsible disclosure practices, initially reporting the vulnerabilities to Versa on February 13, 2025.
Despite acknowledgement and promises of patches, no fixes were delivered by the 90-day disclosure deadline on May 13, 2025.
VulnCheck has assigned three CVEs for the issues:
Until patches are available, organizations should implement temporary mitigations:
“Despite our efforts to responsibly disclose these issues to the Versa team, including multiple follow-ups over the past 90 days, we have not received any response or indication of a forthcoming patch,” the researchers noted.
Organizations using Versa Concerto should take immediate action to implement these mitigations while awaiting official patches.
The severity of these vulnerabilities, combined with their unpatched status, makes this an urgent security concern for affected enterprises.
Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…