THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-23172 (HIGH 7.2) — The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to send crafted HTTP requests to localhost. This

[NVD] CVE-2025-23172 (HIGH 7.2) — The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to send crafted HTTP requests to localhost. This

lownvdPublished 2025-06-19

CVE-2025-23172 CVSS: 7.2 HIGH Published: 2025-06-19T00:15:21.857

The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to send crafted HTTP requests to localhost. This can be leveraged to execute commands on behalf of the

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-23172