CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-24936

CVSS 9.0v3.1pub. 2025-07-21upd. 2025-08-11

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. An attacker with low privileged access to the application has the potential to execute commands on the operating system under the context of the webserver.

🤖 AI Analysis
How it works

The web application passes user input directly to commands executed at the operating system level without proper filtering or validation (CWE-78). The vulnerable component is accessible through the network stack, meaning that potential attacker reach includes the entire Internet. An attacker with a low-privilege account in the application can embed malicious commands in the input data, which will be executed in the context of the web server process.

Impact

An attacker can execute arbitrary operating system commands in the context of the web server account, which may lead to complete system compromise, disclosure of sensitive data, data integrity violations, and service unavailability.

Mitigation & patch

Apply patches available from the manufacturer according to the references (https://www.nokia.com/about-us/security-and-privacy/product-security-advisory/cve-2025-24936/). Until updates are applied, it is recommended to restrict access to the web application only to trusted users and networks, and to monitor system logs for suspicious activity.

Who is affected

Nokia Wavesuite NOC — versions specified in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Nokia Wavesuite Noc

    APP
    Nokia
    23.1223.624.6
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2025-24937CRITICAL9.0PL ✓same product

Nokia Wavesuite NOC — path traversal i RFI umożliwiające pełne przejęcie kontenera

CVE-2025-24938HIGH8.4same product

The web application allows user input to pass unfiltered to a command executed on the underlying operating sys...

CVE-2025-27020CRITICAL9.8PL ✓same vendor

Pominięcie uwierzytelnienia SSH w Nokia Infinera MTC-9 umożliwia RCE

CVE-2025-27019CRITICAL9.8PL ✓same vendor

Nokia Infinera MTC-9: dostęp bez hasła przez usługę RSH umożliwia reverse shell

CVE-2024-25660CRITICAL9.0PL ✓same vendor

Nieautoryzowane operacje na plikach przez WebDAV w Nokia/Infinera TNMS