CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-24937

CVSS 9.0v3.1pub. 2025-07-21upd. 2025-08-11

File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web application and the container it is running on. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. The web application allows arbitrary files to be included in a file that was downloadable and executable by the web server.

🤖 AI Analysis
How it works

The web application allows including (include) arbitrary files into a resource, which is then downloaded and executed by the web server — corresponding to a classic Remote File Inclusion (RFI) vulnerability classified as CWE-98. An attacker can thus read the contents of files from the server's local file system and also place malicious code in the included file. The vulnerable component is accessible from the network (bound to the network stack), which means the scope of potential attackers covers the entire Internet. Low privilege level and access from a neighboring network (vector AV:A) are required.

Impact

An attacker can read sensitive files from the server file system, execute arbitrary code in the context of the web server, and completely take over the web application and container environment in which it is running — compromising the confidentiality, integrity, and availability of the system.

Mitigation & patch

Apply patches available from the vendor according to the references (https://www.nokia.com/about-us/security-and-privacy/product-security-advisory/cve-2025-24937/). Until updates are applied, it is recommended to restrict network access to the vulnerable component and monitor traffic for exploitation attempts.

Who is affected

Nokia Wavesuite NOC — versions indicated in the vendor's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Nokia Wavesuite Noc

    APP
    Nokia
    23.1223.624.6
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2025-24936CRITICAL9.0PL ✓same product

Command injection w Nokia Wavesuite NOC — RCE przez aplikację webową

CVE-2025-24938HIGH8.4same product

The web application allows user input to pass unfiltered to a command executed on the underlying operating sys...

CVE-2025-27020CRITICAL9.8PL ✓same vendor

Pominięcie uwierzytelnienia SSH w Nokia Infinera MTC-9 umożliwia RCE

CVE-2025-27019CRITICAL9.8PL ✓same vendor

Nokia Infinera MTC-9: dostęp bez hasła przez usługę RSH umożliwia reverse shell

CVE-2024-25660CRITICAL9.0PL ✓same vendor

Nieautoryzowane operacje na plikach przez WebDAV w Nokia/Infinera TNMS