CVE-2025-9912 Details
Description
Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.
A local privilege escalation vulnerability exists in Nokia SR Linux. This vulnerability allows an authenticated user to execute arbitrary commands with superuser privileges. It affects all SR Linux versions prior to 23.10.8, 24.10.6, and 25.7.2 (exclusive), across various hardware platforms including the 7215 IXS, 7220 IXR, 7250 IXR, and 7730 SXR.
Users can upgrade to Nokia SR Linux versions 23.10.8, 24.10.6, 25.7.2, or later releases to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-9912/ | Nokia |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Nokia |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | New CVE Received | Nokia |