CVE-2025-24819 Details
Description
Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Software Manager application.
A relative path traversal vulnerability has been identified in Nokia MantaRay NM versions prior to 25R1-NM (exclusive). This vulnerability arises from improper validation of input parameters in the Software Manager application, allowing for unauthorized access to the file system.
Users can upgrade to MantaRay NM version 25R1-NM or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-24819/ | Nokia | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-23 | Relative Path Traversal | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| nokia mantaray nm | < 25r1-nm |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Nokia |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Initial Analysis | [email protected] |
| Apr 7, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2026 | New CVE Received | Nokia |