Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-23169 Details

Description

The Versa Director SD-WAN orchestration platform allows customization of the user interface, including the header, footer, and logo. However, the input provided for these customizations is not properly validated or sanitized, allowing a malicious user to inject and store cross-site scripting (XSS) payloads. Exploitation Status: Versa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers. Workarounds or Mitigation: There are no workarounds to disable the GUI option. Versa recommends that Director be upgraded to one of the remediated software versions.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CISA-ADP

Affected Products

ProductVersions
versa-networks versa director
21.2.2
21.2.3 -
22.1.1
22.1.2 -
22.1.3 -

CPE

  • cpe:2.3:a:versa-networks:versa_director:21.2.2:*:*:*:*:*:*:*
  • cpe:2.3:a:versa-networks:versa_director:21.2.3:-:*:*:*:*:*:*
  • cpe:2.3:a:versa-networks:versa_director:22.1.1:*:*:*:*:*:*:*
  • cpe:2.3:a:versa-networks:versa_director:22.1.2:-:*:*:*:*:*:*
  • cpe:2.3:a:versa-networks:versa_director:22.1.3:-:*:*:*:*:*:*
  • cpe:2.3:a:versa-networks:versa_director:22.1.4:-:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-23169
NVD Published Date:
Jun 19, 2025
NVD Last Modified:
Sep 3, 2026
Source:
[email protected]