{"id":"CVE-2025-24816","title":"Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API","summary":"Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assig…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-284"],"vendor":"nokia","product":"mantaray_nm","affected":["mantaray_nm < 25R2-NM"],"patched":["mantaray_nm 25R2-NM"],"published":"2026-06-30","updated":"2026-09-29","sourceUpdated":"2026-09-29T19:10:00.160","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-24816","references":[{"url":"https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-24816/","label":"b48c3b8f-639e-4c16-8725-497bc411dad0"}],"tags":["nvd"],"epss":0.0034,"epssPercentile":0.24993,"ingestedAt":"2026-09-29T19:44:04.095Z","slug":"CVE-2025-24816","body":"## Overview\n\nNokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assigned privileges.\n\n## Affected\n\n- `mantaray_nm < 25R2-NM`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `mantaray_nm 25R2-NM`","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}