THREAT OPS › Threat News › [NVD] CVE-2025-23170 (MEDIUM 6.7) — The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the user argument. This allows an
[NVD] CVE-2025-23170 (MEDIUM 6.7) — The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the user argument. This allows an
CVE-2025-23170 CVSS: 6.7 MEDIUM Published: 2025-06-19T00:15:21.620
The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the user argument. This allows an attacker to execute arbitrary commands on the system
Indicators of compromise
- CVE-2025-23170cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-23170