CVE-2025-24818

8.0

Nokia · MantaRay NM

Nokia MantaRay NM contains an OS command injection vulnerability in the Log Search application, allowing command execution via improper input neutralization.

Executive summary

An OS command injection vulnerability in the Nokia MantaRay NM Log Search application poses a significant risk of full system compromise for authenticated users.

Vulnerability

This is an OS command injection flaw (CWE-78) residing in the Log Search application, which allows an authenticated attacker with low privileges to execute arbitrary OS commands by injecting malicious characters into the input fields.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands with the privileges of the underlying application service. Given the CVSS score of 8.0, this represents a high-severity risk that could lead to unauthorized system control, data exfiltration, or complete service disruption. The potential for lateral movement within the network following a successful compromise of this management system is substantial.

Remediation

Immediate Action: Upgrade to Nokia MantaRay NM version 25R1-NM or later to resolve the underlying command neutralization flaw.

Proactive Monitoring: Inspect system and application logs for suspicious entries in the Log Search module, specifically looking for shell metacharacters or unauthorized command execution attempts.

Compensating Controls: Implement strict network segmentation and egress filtering to limit the reach of the MantaRay NM system, and utilize a Web Application Firewall to block requests containing suspicious command sequences.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this command injection vulnerability necessitates prompt attention from security administrators. Organizations utilizing Nokia MantaRay NM must prioritize the transition to version 25R1-NM to eliminate the injection vector. Until the patch is applied, access to the Log Search application should be restricted to trusted, highly monitored accounts only.

More Nokia CVEs

Sources