---
id: CVE-2025-24816
title: >-
  Nokia MantaRay is subject to an Improper Access Control vulnerability due to
  insufficient authorization within the API
summary: >-
  Nokia MantaRay is subject to an Improper Access Control vulnerability due to
  insufficient authorization within the API. Successful exploitation could allow
  an authenticated attacker to retrieve confidential information beyond their
  assig…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-284
vendor: nokia
product: mantaray_nm
affected:
  - mantaray_nm < 25R2-NM
patched:
  - mantaray_nm 25R2-NM
published: '2026-06-30'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-24816'
references:
  - url: >-
      https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-24816/
    label: b48c3b8f-639e-4c16-8725-497bc411dad0
tags:
  - nvd
epss: 0.0034
epssPercentile: 0.24993
ingestedAt: '2026-09-29T19:44:04.095Z'
---

## Overview

Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assigned privileges.

## Affected

- `mantaray_nm < 25R2-NM`

## Remediation

Upgrade past the affected range:

- `mantaray_nm 25R2-NM`
