Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-34026 PoC — Versa Concerto SD-WAN 安全漏洞

Source
Associated Vulnerability
Title:Versa Concerto SD-WAN 安全漏洞 (CVE-2025-34026)
Description:Versa Concerto SD-WAN是Versa公司的一个易于使用的用户界面,用于配置和监控安全 SD-WAN 中的 Versa OS设备。 Versa Concerto SD-WAN 12.1.2至12.2.0版本存在安全漏洞,该漏洞源于Traefik反向代理配置中的身份验证绕过,可能导致访问管理端点。
Description
An authentication bypass vulnerability affected the Spring Boot Actuator endpoints in Versa Concerto due to improper handling of the X-Real-Ip header.Attackers could access restricted endpoints by omitting this header.The issue allowed unauthorized access to sensitive functionality, highlighting the need for proper header validation.
File Snapshot

id: CVE-2025-34026 info: name: Versa Concerto Actuator Endpoint - Authentication Bypass author: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.