PatchSiren cyber security CVE debrief
CVE-2025-24815 Nokia CVE debrief
Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to upload malicious files onto the system. This vulnerability has a high impact on users of Nokia MantaRay NM, as it could lead to unauthorized file uploads and potential system compromise. Users should review and apply necessary patches to prevent exploitation.
- Vendor
- Nokia
- Product
- MantaRay NM
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-30
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-06-30
- Advisory updated
- 2026-09-29
Who should care
Users of Nokia MantaRay NM, system administrators, security teams, and operators should review and apply the necessary patches to prevent exploitation of this vulnerability. This vulnerability has a high impact on affected systems and requires immediate attention.
Technical summary
The vulnerability exists due to insufficient file type validation in Nokia MantaRay NM, allowing authenticated attackers to upload malicious files. This could lead to potential system compromise and unauthorized file uploads. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity.
Defensive priority
High
Recommended defensive actions
- Apply patches provided by Nokia
- Restrict file uploads to only allow specific file types
- Monitor system logs for suspicious file upload activity
- Implement additional security controls to prevent exploitation
- Review compensating controls for exposed systems while remediation is scheduled and verified
Evidence notes
The CVE record was published on 2026-06-30T10:16:32.473Z and was last modified on 2026-07-10T17:07:58.220Z. The source details indicate an unrestricted file upload vulnerability in Nokia MantaRay NM due to insufficient file type validation. Evidence is limited to CVE and NVD details. Defenders should verify affected product deployments, review official advisories, and plan for vendor-supported updates or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-24815 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-24815
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-24815 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-24815
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-24815/
b48c3b8f-639e-4c16-8725-497bc411dad0 - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.