#VU122035 Improper authentication in SD-WAN - CVE-2025-34026

 

#VU122035 Improper authentication in SD-WAN - CVE-2025-34026

Published: January 26, 2026


Vulnerability identifier: #VU122035
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: CVE-2025-34026
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
SD-WAN
Software vendor:
Versa Networks

Description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to missing authentication checks in the Traefik reverse proxy configuration. A remote non-authenticated attacker can bypass authentication process and gain unauthorized access to administrative endpoints. The vulnerability allows an attacker to obtain heap dumps and trace logs and use this information to compromise the affected system. 


Remediation

Install updates from vendor's website.

External links