Open Redirect Vulnerability in NSP by Nokia
CVE-2026-40465

5.3MEDIUM

Key Information:

Vendor

Nokia

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-40465?

The NSP by Nokia contains a vulnerability that allows for open redirects, stemming from inadequate server-side validation of the URL parameter. This weakness can be exploited to redirect users to potentially malicious sites, posing significant risks to user security and data integrity. It is crucial for administrators and users to be aware of this vulnerability and apply the necessary updates to mitigate the associated risks. For further details and guidance, please refer to the Nokia Product Security Advisory.

Affected Version(s)

NSP 23.11

NSP 24.4

NSP 24.8

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.