CVE-2025-24936 Details
Description
The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. An attacker with low privileged access to the application has the potential to execute commands on the operating system under the context of the webserver.
A command injection vulnerability has been identified in Nokia WaveSuite NOC versions WS-NOC 24.6, WS-NOC 23.6, and WS-NOC 23.12. This vulnerability allows user input to be passed unfiltered to a command executed on the underlying operating system. The affected component is connected to the network stack, potentially exposing the vulnerability to attackers across the Internet. An individual with low privileged access to the application could exploit this issue to execute commands on the operating system, under the context of the web server.
Users can upgrade to Nokia WaveSuite NOC 24.6 FP3 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.nokia.com/about-us/security-and-privacy/product-security-advisory/cve-2025-24936/ | Nokia | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| nokia wavesuite noc | 23.6 23.12 24.6 - |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Nokia |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 11, 2025 | Initial Analysis | [email protected] |
| Jul 23, 2025 | CVE Modified | CISA-ADP |
| Jul 21, 2025 | New CVE Received | Nokia |