Input Handling Flaw in ONT/Beacon Device from Nokia
CVE-2025-9974

8HIGH

Key Information:

Vendor

Nokia

Status
Vendor
CVE Published:
2 February 2026

What is CVE-2025-9974?

The ONT/Beacon device by Nokia features a critical input handling flaw in its unified WEBUI application. This vulnerability allows low-privileged authenticated users to exploit insufficient validation of user-supplied data, enabling them to execute arbitrary commands on the device's operating system. Such exploitation could compromise the device's confidentiality, integrity, and availability, posing a serious security threat to users reliant on the ONT/Beacon system.

Affected Version(s)

Nokia ONT Releases prior to BBDR2503

Nokia ONT Releases prior to BBDR2503

Nokia ONT BBDR2503 and later releases

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.