CVE-2025-27023 is a medium-severity vulnerability affecting Infinera G42 R6.1.3 and Nokia G42 firmware, stemming from insufficient input validation in the WebGUI CLI. An authenticated remote attacker can exploit this to read any operating system file by crafting specific CLI commands. The vulnerability has a CVSS score of 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N), indicating it can be exploited over the network with low complexity and requires low privileges, leading to high confidentiality impact. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is there any evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.1.3, < 7.1CPE matchmatch criteria | cpe:2.3:o:nokia:g42_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.