THREAT OPS › Threat News › [NVD] CVE-2025-24291 (MEDIUM 6.1) — The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME typ
[NVD] CVE-2025-24291 (MEDIUM 6.1) — The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME typ
CVE-2025-24291 CVSS: 6.1 MEDIUM Published: 2025-06-19T00:15:22.437
The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allowing the upload of arbitrary file
MITRE ATT&CK techniques
- Malicious FileT1204.002
Indicators of compromise
- CVE-2025-24291cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-24291