File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web application and the container it is running on. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. The web application allows arbitrary files to be included in a file that was downloadable and executable by the web server.
The web application allows including (include) arbitrary files into a resource, which is then downloaded and executed by the web server — corresponding to a classic Remote File Inclusion (RFI) vulnerability classified as CWE-98. An attacker can thus read the contents of files from the server's local file system and also place malicious code in the included file. The vulnerable component is accessible from the network (bound to the network stack), which means the scope of potential attackers covers the entire Internet. Low privilege level and access from a neighboring network (vector AV:A) are required.
An attacker can read sensitive files from the server file system, execute arbitrary code in the context of the web server, and completely take over the web application and container environment in which it is running — compromising the confidentiality, integrity, and availability of the system.
Apply patches available from the vendor according to the references (https://www.nokia.com/about-us/security-and-privacy/product-security-advisory/cve-2025-24937/). Until updates are applied, it is recommended to restrict network access to the vulnerable component and monitor traffic for exploitation attempts.
Nokia Wavesuite NOC — versions indicated in the vendor's references
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HNokia Wavesuite Noc
APPNokia23.1223.624.6
Related vulnerabilities
Command injection w Nokia Wavesuite NOC — RCE przez aplikację webową
The web application allows user input to pass unfiltered to a command executed on the underlying operating sys...
Pominięcie uwierzytelnienia SSH w Nokia Infinera MTC-9 umożliwia RCE
Nokia Infinera MTC-9: dostęp bez hasła przez usługę RSH umożliwia reverse shell
Nieautoryzowane operacje na plikach przez WebDAV w Nokia/Infinera TNMS