CVE-2025-27020 Details
Description
Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system . This issue affects MTC-9: from R22.1.1.0275 before R23.0.
A vulnerability exists in Infinera MTC-9 versions R22.1.1.0275 prior to R23.0 due to improper SSH service configuration. This misconfiguration allows unauthenticated attackers to execute arbitrary commands and access filesystem data via SSH. The issue arises from specific password-less users being able to perform actions not intended for system command-line interface logins.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 8, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cvcn.gov.it/cvcn/cve/CVE-2025-27020 | ENISA | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | ENISA |
Affected Products
| Product | Versions |
|---|---|
| nokia infinera mtc-9 firmware | >= 22.1.1.0275, < 23.0 |
CPE
Remediation
| |
| nokia infinera mtc-9 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ENISA |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 22, 2025 | Initial Analysis | [email protected] |
| Dec 8, 2025 | New CVE Received | ENISA |