ZeroHour

Vulnerabilities

109 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-24815
+2 in the same advisory: …7406 …24816
Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation.

Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to upload malicious files onto the system.

NVD description · AI analysis pending
7.8
group max
<1%
  • nokia mantaray nm
CVE-2022-45899
Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Lo

Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field.

NVD description · AI analysis pending
6.51% PoC
  • nokia broadcast message center
CVE-2025-24818
+2 in the same advisory: …24817 …24819
Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search application.

NVD description · AI analysis pending
8.0
group max
1%
  • nokia mantaray nm
CVE-2023-31044
+1 in the same advisory: …35486
An issue was discovered in Nokia Impact before Mobile 23_FP1.

An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate data fields that may attempt data exfiltration or other malicious activity when automatically executed by the spreadsheet software.

NVD description · AI analysis pending
8.8
group max
<1%
  • nokia impact mobile
CVE-2021-35484
+2 in the same advisory: …35485 …35483
Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/re

Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version information.

NVD description · AI analysis pending
8.2
group max
<1%
  • nokia impact
CVE-2025-10258
Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive informatio

Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive information.

NVD description · AI analysis pending
6.3<1%
  • nokia infinera dna
CVE-2025-27020
+4 in the same advisory: …27019 …26487 …26488 …26489
Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system .

Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system . This issue affects MTC-9: from R22.1.1.0275 before R23.0.

NVD description · AI analysis pending
9.8
group max
<1%
  • nokia infinera mtc-9 firmware
CVE-2025-24936
+2 in the same advisory: …24937 …24938
The web application allows user input to pass unfiltered to a command executed on the underlying operating system.

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. An attacker with low privileged access to the application has the potential to execute commands on the operating system under the context of the webserver.

NVD description · AI analysis pending
9.0
group max
<1%
  • nokia wavesuite noc
CVE-2025-27021
+4 in the same advisory: …27022 …27023 …27024 …27026
The misconfiguration in the sudoers configuration of the operating system in Infinera G42 version R6.1.3 allows low privileged OS users to read/write physical m

The misconfiguration in the sudoers configuration of the operating system in Infinera G42 version R6.1.3 allows low privileged OS users to read/write physical memory via devmem command line tool. This could allow sensitive information disclosure, denial of service, and privilege escalation by tampering with kernel memory. Details: The output of "sudo -l" reports the presence of "devmem" command executable as super user without using a password. This command allows to read and write an arbitrary memory area of the target device, specifying an absolute address.

NVD description · AI analysis pending
7.8
group max
<1%
  • nokia g42 firmware
CVE-2024-25660
+3 in the same advisory: …25661 …25659 …25658
The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operation

The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.

NVD description · AI analysis pending
9.0
group max
<1%
  • nokia transcend network management system
CVE-2024-28812
An issue was discovered in Infinera hiT 7300 5.60.50.

An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection.

NVD description · AI analysis pending
8.8
group max
<1%
  • nokia hit 7300 firmware
CVE-2022-39818
In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter.

In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system.

NVD description · AI analysis pending
8.8
group max
2% PoC
  • nokia network functions manager for transport
CVE-2023-41351
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mecha

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.

NVD description · AI analysis pending
9.8
group max
<1%
  • nokia g-040w-q firmware