The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. An attacker with low privileged access to the application has the potential to execute commands on the operating system under the context of the webserver.
The web application passes user input directly to commands executed at the operating system level without proper filtering or validation (CWE-78). The vulnerable component is accessible through the network stack, meaning that potential attacker reach includes the entire Internet. An attacker with a low-privilege account in the application can embed malicious commands in the input data, which will be executed in the context of the web server process.
An attacker can execute arbitrary operating system commands in the context of the web server account, which may lead to complete system compromise, disclosure of sensitive data, data integrity violations, and service unavailability.
Apply patches available from the manufacturer according to the references (https://www.nokia.com/about-us/security-and-privacy/product-security-advisory/cve-2025-24936/). Until updates are applied, it is recommended to restrict access to the web application only to trusted users and networks, and to monitor system logs for suspicious activity.
Nokia Wavesuite NOC — versions specified in the manufacturer's references
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HNokia Wavesuite Noc
APPNokia23.1223.624.6
Related vulnerabilities
Nokia Wavesuite NOC — path traversal i RFI umożliwiające pełne przejęcie kontenera
The web application allows user input to pass unfiltered to a command executed on the underlying operating sys...
Pominięcie uwierzytelnienia SSH w Nokia Infinera MTC-9 umożliwia RCE
Nokia Infinera MTC-9: dostęp bez hasła przez usługę RSH umożliwia reverse shell
Nieautoryzowane operacje na plikach przez WebDAV w Nokia/Infinera TNMS