Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nokia

First CVE: Jun 2, 2001Active for: 25 yearsTotal CVEs: 150
40.0
VTI Score
Medium

Nokia's vulnerability footprint spans a moderately broad portfolio of telecommunications network management, optical systems, and infrastructure products—including platforms such as NetAct, the 1350 Optical Management System, and HIT appliances—that operate in critical network environments. Vulnerabilities affecting the vendor skew toward serious outcomes with a meaningful share reaching critical severity and frequently acquire public exploit code, reflecting the operational technology and management-interface exposure of these platforms. The recurring weakness classes center on input-handling and access-control defects including cross-site scripting, path traversal, OS command injection, and improper input validation, which are characteristic of web-facing management consoles and command-processing interfaces embedded in network infrastructure. Defenders should treat Nokia infrastructure advisories as high-priority for affected deployments and prioritize isolation and access controls around management interfaces; live exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
150
Total CVEs
More Total CVEs than 99% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nokia over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 2, 2001
25 years ago
Most Recent CVE
Jun 30, 2026
24 days ago

Self-Reporting Analysis

Of all the CVEs published by Nokia as a CNA, 38.5% affect products that Nokia develops as a vendor.

38.5%
61.5%
Self-reported: 10 (38.5%)
Third-party: 16 (61.5%)

Of all the CVEs published that affect products developed by Nokia, 6.7% are self-published by Nokia as a CNA.

93.3%
Self-published: 10 (6.7%)
Other CNAs: 140 (93.3%)

Products(110 total)

Top CVEs

Signals from CVEs in this vendor scope (150 CVEs).

150 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-3921HIGH
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, authenticated at
Mar 5, 20198.847NOYES
CVE-2005-2277HIGH
Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command
Jul 15, 200510.041NOYES
CVE-2021-31932CRITICAL
Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web p
Feb 11, 20229.840NONO
CVE-2011-0498HIGH
Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and pos
Jan 20, 20119.339NOYES
CVE-2009-0734HIGH
Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file
Feb 25, 20099.335NOYES
CVE-2009-0649HIGH
The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) via JavaScript code that calls the setAttributeNode method.
Feb 20, 20097.835NOYES
CVE-2005-2250HIGH
Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share.
Jul 13, 20057.534NOYES
CVE-2025-7406HIGH
Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root pri
Jun 30, 20267.833NONO
CVE-2025-24815HIGH
Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to
Jun 30, 20267.832NONO
CVE-2025-27020CRITICAL
Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system . This issue affects
Dec 8, 20259.832NONO
View all 150 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products150 CVEs
41%
46%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local20 (13.3%)
Network77 (51.3%)
Unknown40 (26.7%)
Physical0 (0.0%)
Adjacent Network13 (8.7%)
Attack Complexity
Low107 (71.3%)
High3 (2.0%)
Unknown40 (26.7%)
User Interaction
None85 (56.7%)
Unknown40 (26.7%)
Required25 (16.7%)
Privileges Required
Low61 (40.7%)
High12 (8.0%)
None37 (24.7%)
Unknown40 (26.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (150 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
17 CVEs
11.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nokia.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nokia — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nokia's Products

View all 7 CNAs →

Top CWEs