CVE-2025-26489 Details
Description
Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the service and reboot the appliance, thus causing a DoS condition, via crafted XML payloads.This issue affects MTC-9: from R22.1.1.0275 before R23.0.
A denial-of-service vulnerability has been identified in the Netconf service of Infinera MTC-9, specifically in versions from R22.1.1.0275 prior to R23.0. This vulnerability allows remote authenticated users to cause the service to crash and reboot the appliance by sending crafted XML payloads, thereby creating a DoS condition.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cve.org/CVERecord?id=CVE-2025-26489 | ENISA | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | ENISA |
Affected Products
| Product | Versions |
|---|---|
| nokia infinera mtc-9 firmware | >= 22.1.1.0275, < 23.0 |
CPE
Remediation
| |
| nokia infinera mtc-9 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ENISA |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 22, 2025 | Initial Analysis | [email protected] |
| Dec 8, 2025 | CVE Modified | ENISA |
| Dec 8, 2025 | New CVE Received | ENISA |