← All Advisories

CVE-2025-7406

Status: UPDATED  |  Advisory ID: CVE-2025-7406

Key Details

CVECVE-2025-7406
CVSSCVSS 7.8 (High).
Affected productsNokia mantaray_nm
Classified asCWE-269 (Improper Privilege Management)

What to Know

Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-7406
Vendor advisoryhttps://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-7406/