CVE-2025-23168: High severity Versa Networks Versa Director vulnerability

Published Jun 18, 2025
·
Updated

The Versa Director SD-WAN orchestration platform implements Two-Factor Authentication (2FA) using One-Time Passcodes (OTP) delivered via email or SMS. Versa Director accepts untrusted user input when dispatching 2FA codes, allowing an attacker who knows a valid username and password to redirect the OTP delivery (SMS/email) to their own device. OTP/TOTP codes are not invalidated after use, enabling reuse by an attacker who has previously intercepted or obtained a valid code. In addition, the 2FA system does not adequately restrict the number or frequency of login attempts. The OTP values are generated from a relatively small keyspace, making brute-force attacks more feasible. Exploitation Status: Versa Networks is not aware of any reported instance where this vulnerability was exploited. Proof of concept for this vulnerability has been disclosed by third party security researchers. Workarounds or Mitigation: Versa recommends that Director be upgraded to one of the remediated software versions.

Affected Software

6 affected components
Versa Networks Versa Director
Versa-networks Versa Director=21.2.2
Versa-networks Versa Director=21.2.3
Versa-networks Versa Director=22.1.2
Versa-networks Versa Director=22.1.3
Versa-networks Versa Director=22.1.4

Event History

Jun 18, 2025
CVE Published
via MITRE·11:30 PM
Data Sourced
via MITRE·11:30 PM
DescriptionSeverity
Jun 19, 2025
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-23168?

CVE-2025-23168 is classified as a high severity vulnerability due to its potential for unauthorized access through compromised two-factor authentication.

2

How do I fix CVE-2025-23168?

To fix CVE-2025-23168, ensure that your deployment of Versa Director is updated to the latest version where the vulnerability has been addressed.

3

What type of attack does CVE-2025-23168 allow?

CVE-2025-23168 allows attackers to redirect One-Time Passcodes (OTPs) and potentially gain unauthorized access to user accounts.

4

Which software is affected by CVE-2025-23168?

CVE-2025-23168 affects the Versa Networks Versa Director orchestration platform.

5

Is user input validation a concern in CVE-2025-23168?

Yes, CVE-2025-23168 highlights an issue with untrusted user input being processed when dispatching OTPs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203