Command Execution Vulnerability in Nokia's Web Application
CVE-2025-24936

9CRITICAL

Key Information:

Vendor

Nokia

Vendor
CVE Published:
21 July 2025

What is CVE-2025-24936?

A critical security vulnerability exists in Nokia's web application, allowing unfiltered user input to be executed as commands on the underlying operating system. This flaw, which can be exploited by attackers with low privileged access, jeopardizes the integrity and security of the system. Given that the vulnerable component interfaces with the network stack, the potential for exploitation extends to a wide range of threat actors online. It is essential for users and administrators to take immediate action to mitigate this risk and protect their systems.

Affected Version(s)

WaveSuite NOC WS-NOC 24.6, WS-NOC 23.6 and WS-NOC 23.12

WaveSuite NOC WS-NOC 24.6 FP3

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.