THREAT OPS › Threat News › [NVD] CVE-2025-23172 (HIGH 7.2) — The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to send crafted HTTP requests to localhost. This
[NVD] CVE-2025-23172 (HIGH 7.2) — The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to send crafted HTTP requests to localhost. This
CVE-2025-23172 CVSS: 7.2 HIGH Published: 2025-06-19T00:15:21.857
The Versa Director SD-WAN orchestration platform includes a Webhook feature for sending notifications to external HTTP endpoints. However, the "Add Webhook" and "Test Webhook" functionalities can be abused by an authenticated user to send crafted HTTP requests to localhost. This can be leveraged to execute commands on behalf of the
Indicators of compromise
- CVE-2025-23172cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-23172