---
id: CVE-2025-24815
title: >-
  Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due
  to insufficient file type validation
summary: >-
  Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due
  to insufficient file type validation. Successful exploitation could allow an
  authenticated attacker to upload malicious files onto the system.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: nokia
product: mantaray_nm
affected:
  - mantaray_nm < 25R2-NM
patched:
  - mantaray_nm 25R2-NM
published: '2026-06-30'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-24815'
references:
  - url: >-
      https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-24815/
    label: b48c3b8f-639e-4c16-8725-497bc411dad0
tags:
  - nvd
epss: 0.00162
epssPercentile: 0.04632
ingestedAt: '2026-09-29T19:44:04.095Z'
---

## Overview

Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to upload malicious files onto the system.

## Affected

- `mantaray_nm < 25R2-NM`

## Remediation

Upgrade past the affected range:

- `mantaray_nm 25R2-NM`
