Improper authentication in SD-WAN - CVE-2025-34026

 

Improper authentication in SD-WAN - CVE-2025-34026

Published: January 26, 2026


Vulnerability identifier: #VU122035
CSH Severity: Critical
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: CVE-2025-34026
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vendor: Versa Networks
Affected software:
SD-WAN

Detailed vulnerability description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to missing authentication checks in the Traefik reverse proxy configuration. A remote non-authenticated attacker can bypass authentication process and gain unauthorized access to administrative endpoints. The vulnerability allows an attacker to obtain heap dumps and trace logs and use this information to compromise the affected system. 


How to mitigate CVE-2025-34026

Install updates from vendor's website.

Sources