---
id: CVE-2025-7406
title: >-
  Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability
  where a local attacker possessing administrative (local admin) privileges can
  escalate to full root privileges on the host
summary: >-
  Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability
  where a local attacker possessing administrative (local admin) privileges can
  escalate to full root privileges on the host. Successful exploitation results
  in r…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: nokia
product: mantaray_nm
affected:
  - mantaray_nm < 25R2-NM
patched:
  - mantaray_nm 25R2-NM
published: '2026-06-30'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-7406'
references:
  - url: >-
      https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-7406/
    label: b48c3b8f-639e-4c16-8725-497bc411dad0
tags:
  - nvd
epss: 0.00137
epssPercentile: 0.02587
ingestedAt: '2026-09-29T19:44:04.096Z'
---

## Overview

Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts.

## Affected

- `mantaray_nm < 25R2-NM`

## Remediation

Upgrade past the affected range:

- `mantaray_nm 25R2-NM`
