CVE-2025-24819Medium· 5.7▾ SunlitNokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Software Manager application.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Software Manager application.
mantaray_nm < 25r1-nmUpgrade past the affected range:
mantaray_nm 25r1-nmConnected by shared product, vendor, weakness, or advisory.
CVE-2025-24817High· 8.0Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application.
CVE-2025-24818High· 8.0Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search application.
CVE-2025-7406High· 7.8Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host
CVE-2025-24815High· 7.8Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation
CVE-2025-24816Medium· 6.5Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API
CVE-2022-45899Medium· 6.5Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field.