A critical vulnerability, CVE-2025-34027, has been identified in the Versa Concerto SD-WAN orchestration platform, affecting versions 12.1.2 through 12.2.0. This flaw results from a misconfiguration in the Traefik reverse proxy that enables authentication bypass, granting unauthorized access to administrative endpoints. Exploiting the vulnerable Spack upload endpoint, attackers can leverage a Time-of-Check to Time-of-Use (TOCTOU) race condition to manipulate file paths during load operations. This enables unauthenticated remote code execution (RCE) on the underlying system. The IONIX research team confirmed the impact through controlled exploit validation, as detailed in this post.
References:

