CVE-2019-25029: Versa-Networks Versa Director
Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.
In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP headers etc.) to a system shell. In this attack, the attacker-supplied operating system commands are usually executed with the privileges of the vulnerable application. Command injection attacks are possible largely due to insufficient input validation.
Affected products
- Versa-Networks Versa Director: before 16.1R2S11 (fixed in 16.1R2S11); from 20.2.0, before 20.2.2 (fixed in 20.2.2); from 21.1.0, before 21.1.1 (fixed in 21.1.1); from 21.2.0, before 21.2.1 (fixed in 21.2.1)
Published 2021-05-26. Last modified 2026-08-31.