THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-23170 (MEDIUM 6.7) — The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the user argument. This allows an

[NVD] CVE-2025-23170 (MEDIUM 6.7) — The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the user argument. This allows an

lownvdPublished 2025-06-19

CVE-2025-23170 CVSS: 6.7 MEDIUM Published: 2025-06-19T00:15:21.620

The Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via Shell-In-A-Box. The underlying Python script, shell-connect.py, is vulnerable to command injection through the user argument. This allows an attacker to execute arbitrary commands on the system

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-23170