PatchSiren

Nokia CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Nokia CVE published 2026-06-30

CVE-2025-24816

Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assigned privileges. This vulnerability affects users with access to the API, particularly those managing Nokia MantaRay Nm deployments. The vulnerability has a CVSS score of 6 [truncated]

HIGH Nokia CVE published 2026-06-30

CVE-2025-24815

Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to upload malicious files onto the system. This vulnerability has a high impact on users of Nokia MantaRay NM, as it could lead to unauthorized file uploads and potential system compromise. Users should review and apply necessary [truncated]

MEDIUM Nokia CVE published 2026-06-16

CVE-2025-9912

CVE-2025-9912 is a local privilege escalation vulnerability in Nokia SR Linux. An authenticated user may exploit this vulnerability to execute arbitrary commands with superuser privilege.

MEDIUM Nokia CVE published 2026-06-16

CVE-2025-10262

CVE-2025-10262 is a local privilege escalation vulnerability in Nokia SR Linux due to unsanitized format validation. An authenticated user could exploit this to execute arbitrary commands with superuser privileges.