THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-24291 (MEDIUM 6.1) — The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME typ

[NVD] CVE-2025-24291 (MEDIUM 6.1) — The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME typ

lownvdPublished 2025-06-19

CVE-2025-24291 CVSS: 6.1 MEDIUM Published: 2025-06-19T00:15:22.437

The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the file name, an attacker can bypass MIME type validation, allowing the upload of arbitrary file

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-24291