CVE-2025-24818 is an OS command injection vulnerability affecting Nokia MantaRay NM, specifically in the Log Search application, caused by inadequate sanitization of special elements in operating system commands. The vulnerability carries a CVSS score of 8.0 (HIGH) with a vector of CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating high severity across confidentiality, integrity, and availability. Exploitation requires adjacent network access and valid user privileges with low complexity, but no user interaction is necessary. Currently, there is no evidence of active exploitation, as the vulnerability is not listed in the Known Exploited Vulnerabilities catalog and demonstrates minimal community attention with an EPSS score of 0.00055. Organizations operating Nokia MantaRay NM should prioritize patching this vulnerability given its high severity and the authenticated access pathway available to internal users.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 25r1-nmCPE matchmatch criteria | cpe:2.3:a:nokia:mantaray_nm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.