CVE-2025-24815 Details
Description
Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to upload malicious files onto the system.
A vulnerability allowing unrestricted file upload has been identified in Nokia MantaRay NM. This issue arises from inadequate validation of file types, enabling authenticated attackers to upload malicious files to the system. The vulnerability affects all MantaRay versions prior to 25R2-NM (exclusive).
Users can upgrade to MantaRay NM version 25R2-NM or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-24815/ | Nokia | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| nokia mantaray nm | < 25R2-NM |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | Initial Analysis | [email protected] |
| Jun 30, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | CVE Modified | Nokia |
| Jun 30, 2026 | New CVE Received | Nokia |