Improper authentication in SD-WAN - CVE-2025-34026

 

Improper authentication in SD-WAN - CVE-2025-34026

Published: January 26, 2026


Vulnerability identifier: #VU122035
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-34026
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to missing authentication checks in the Traefik reverse proxy configuration. A remote non-authenticated attacker can bypass authentication process and gain unauthorized access to administrative endpoints. The vulnerability allows an attacker to obtain heap dumps and trace logs and use this information to compromise the affected system. 


Affected software

SD-WAN

How to mitigate CVE-2025-34026

Install updates from vendor's website.

SD-WAN - update to 12.1.2 Hotfix

External References

Related Security Bulletins