VYPR

Vendor CVEs

Nokia

All CVEs

167 total · sorted by risk
  • CVE-2021-31932CriFeb 11, 2022
    risk 0.65cvss 9.8epss 0.22

    Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using URL encoding for the . (dot) character.

  • CVE-2025-27020CriDec 8, 2025
    risk 0.64cvss 9.8epss 0.00

    Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system . This issue affects MTC-9: from R22.1.1.0275 before R23.0.

  • CVE-2025-27019CriDec 8, 2025
    risk 0.64cvss 9.8epss 0.00

    Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system access by activating a reverse shell.This issue affects MTC-9: from R22.1.1.0275 before R23.0.

  • CVE-2023-41355CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of…

  • CVE-2023-41351CriNov 3, 2023
    risk 0.64cvss 9.8epss 0.01

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log…

  • CVE-2022-39815CriSep 13, 2022
    risk 0.64cvss 9.8epss 0.02

    In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system.

  • CVE-2021-41487CriJun 16, 2022
    risk 0.64cvss 9.8epss 0.02

    NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.

  • CVE-2019-3922CriMar 5, 2019
    risk 0.64cvss 9.8epss 0.05

    The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, unauthenticated attacker to /GponForm/fsetup_Form. An attacker can leverage this vulnerability to potentially…

  • CVE-2019-3918CriMar 5, 2019
    risk 0.64cvss 9.8epss 0.02

    The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH interfaces.

  • CVE-2019-3921HigMar 5, 2019
    risk 0.62cvss 8.8epss 0.18

    The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, authenticated attacker to /GponForm/usb_Form?script/. An attacker can leverage this vulnerability to potentially…

  • CVE-2025-24937CriJul 21, 2025
    risk 0.59cvss 9.0epss 0.00

    File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web application and the container it is running on. The vulnerable component is bound to the network stack and…

  • CVE-2025-24936CriJul 21, 2025
    risk 0.59cvss 9.0epss 0.00

    The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. An attacker with low…

  • CVE-2024-25660CriOct 1, 2024
    risk 0.59cvss 9.0epss 0.01

    The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.

  • CVE-2019-3920HigMar 5, 2019
    risk 0.58cvss 8.8epss 0.04

    The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP request sent by a remote, authenticated attacker to /GponForm/device_Form?script/.

  • CVE-2019-3919HigMar 5, 2019
    risk 0.58cvss 8.8epss 0.04

    The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent by a remote, authenticated attacker to /GponForm/usb_restore_Form?script/.

  • CVE-2023-49564HigSep 18, 2025
    risk 0.57cvss 8.8epss 0.00

    The CBIS/NCS Manager API is vulnerable to an authentication bypass. By sending a specially crafted HTTP header, an unauthenticated user can gain unauthorized access to API functions. This flaw allows attackers to reach restricted or sensitive endpoints of the HTTP API without…

  • CVE-2024-28812HigSep 30, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection.

  • CVE-2024-28809HigSep 30, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.

  • CVE-2022-39822HigDec 25, 2023
    risk 0.57cvss 8.8epss 0.01

    In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation.

  • CVE-2022-39818HigDec 25, 2023
    risk 0.57cvss 8.8epss 0.02

    In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system.

  • CVE-2023-41353HigNov 3, 2023
    risk 0.57cvss 8.8epss 0.01

    Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system…

  • CVE-2022-41763HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the…

  • CVE-2022-30280HigJul 24, 2023
    risk 0.57cvss 8.8epss 0.00

    /SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a…

  • CVE-2022-28864HigJul 24, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim…

  • CVE-2022-28863HigJul 24, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the…

  • CVE-2022-30759HigMay 2, 2023
    risk 0.57cvss 8.8epss 0.01

    In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and execute arbitrary commands.

  • CVE-2022-28866HigOct 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not properly validate requests for access to (or editing of) data and functionality in all endpoints under /#settings/* and /api/settings/*. By not verifying the…

  • CVE-2022-39819HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execute commands on the operating system.

  • CVE-2022-39817HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected)…

  • CVE-2021-45896HigDec 27, 2021
    risk 0.57cvss 8.8epss 0.02

    Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of Import Config File.

  • CVE-2019-17403HigNov 25, 2019
    risk 0.57cvss 8.8epss 0.03

    Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.

  • CVE-2025-26487HigDec 8, 2025
    risk 0.56cvss 8.6epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resources using HTTPS requests through the appliance used as a bridge.

  • CVE-2023-49565HigSep 18, 2025
    risk 0.55cvss 8.4epss 0.01

    The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sanitization of the HTTP Headers X-FILENAME, X-PAGE, and X-FIELD allows for command injection. These headers are directly utilized within the subprocess.Popen…

  • CVE-2025-24938HigJul 21, 2025
    risk 0.55cvss 8.4epss 0.00

    The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged access (administrator) to the application has the potential execute commands on the operating system under the context of the…

  • CVE-2024-28813HigSep 30, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activate remote SSH access to the appliance via an unexpected network interface.

  • CVE-2022-2484HigJan 6, 2023
    risk 0.55cvss 8.4epss 0.00

    The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This could result in the execution of a malicious kernel, arbitrary programs, or modified Nokia programs.

  • CVE-2022-2483HigJan 6, 2023
    risk 0.55cvss 8.4epss 0.00

    The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device.

  • CVE-2022-2482HigJan 6, 2023
    risk 0.55cvss 8.4epss 0.00

    A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the appropriate place could allow for arbitrary code execution in…

  • CVE-2022-36222HigDec 21, 2022
    risk 0.55cvss 8.4epss 0.00

    Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used locally to access the web admin interface.

  • CVE-2021-35486HigMar 3, 2026
    risk 0.53cvss 8.1epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor…

  • CVE-2021-35484HigMar 3, 2026
    risk 0.53cvss 8.2epss 0.00

    Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker…

  • CVE-2023-22618HigOct 4, 2023
    risk 0.53cvss 8.1epss 0.00

    If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, WaveLite…

  • CVE-2025-24818HigApr 7, 2026
    risk 0.52cvss 8.0epss 0.01

    Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search application.

  • CVE-2025-24817HigApr 7, 2026
    risk 0.52cvss 8.0epss 0.01

    Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application.

  • CVE-2021-35485HigMar 3, 2026
    risk 0.52cvss 8.0epss 0.00

    The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application,…

  • CVE-2025-9974HigFeb 2, 2026
    risk 0.52cvss 8.0epss 0.00

    The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users to trigger unintended system-level command execution. Due to insufficient validation of user-supplied data, a low-privileged authenticated attacker may be able…

  • CVE-2022-31244HigApr 25, 2023
    risk 0.51cvss 7.8epss 0.00

    Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.

  • CVE-2021-32288HigSep 20, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicHeight() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.

  • CVE-2021-32287HigSep 20, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicWidth() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.

  • CVE-2024-25661HigOct 1, 2024
    risk 0.50cvss 7.7epss 0.00

    In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators to obtain various users' passwords by reading memory dumps of the desktop application.

Page 1 of 4