Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-34026

96
FAUCET Score

CVE-2025-34026 is an authentication bypass vulnerability affecting the Versa Concerto SD-WAN orchestration platform, specifically versions 12.1.2 through 12.2.0. This high-severity flaw (CVSS 7.5) allows unauthenticated attackers to access administrative endpoints and sensitive data like heap dumps via a misconfigured Traefik reverse proxy. The vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog. Critical-severity Nuclei templates are available, and it has generated significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 11.4.0, < 12.1.2CPE matchmatch criteria
cpe:2.3:a:versa-networks:concerto:*:*:*:*:*:*:*:*
12.1.2CPE matchmatch criteria
cpe:2.3:a:versa-networks:concerto:12.1.2:-:*:*:*:*:*:*
12.2.0CPE matchmatch criteria
cpe:2.3:a:versa-networks:concerto:12.2.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.2CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
83.23%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · Jan 22, 2026
Nuclei: CVE-2025-34026 · May 22, 2025
This CVE's current EPSS score of 0.8323 is in the 100th percentile among its peer group of 51,455 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

security-portal.versa-networks.com / emailbulletins/6830f94328defa375486ff2e
Vendor Advisory
cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
projectdiscovery.io / blog/versa-concerto-authentication-bypass-rce
ExploitMitigationThird Party Advisory