---
id: CVE-2025-10262
title: >-
  Nokia SR Linux is vulnerable to local privilege escalation vulnerability due
  to unsanitized format validation
summary: >-
  Nokia SR Linux is vulnerable to local privilege escalation vulnerability due
  to unsanitized format validation. Successful exploitation of this
  vulnerability may allow an authenticated user to execute arbitrary commands
  with superuser pri…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H'
cwe:
  - CWE-134
published: '2026-06-16'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10262'
references:
  - url: >-
      https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-10262/
    label: b48c3b8f-639e-4c16-8725-497bc411dad0
tags:
  - nvd
epss: 0.00116
epssPercentile: 0.01469
ingestedAt: '2026-09-30T21:25:07.748Z'
---

## Overview

Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
