Nokia's vulnerability footprint spans a moderately broad portfolio of telecommunications network management, optical systems, and infrastructure products—including platforms such as NetAct, the 1350 Optical Management System, and HIT appliances—that operate in critical network environments. Vulnerabilities affecting the vendor skew toward serious outcomes with a meaningful share reaching critical severity and frequently acquire public exploit code, reflecting the operational technology and management-interface exposure of these platforms. The recurring weakness classes center on input-handling and access-control defects including cross-site scripting, path traversal, OS command injection, and improper input validation, which are characteristic of web-facing management consoles and command-processing interfaces embedded in network infrastructure. Defenders should treat Nokia infrastructure advisories as high-priority for affected deployments and prioritize isolation and access controls around management interfaces; live exploitation and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nokia over time
Of all the CVEs published by Nokia as a CNA, 38.5% affect products that Nokia develops as a vendor.
Of all the CVEs published that affect products developed by Nokia, 6.7% are self-published by Nokia as a CNA.
Signals from CVEs in this vendor scope (150 CVEs).
150 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3921HIGH The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, authenticated at | Mar 5, 2019 | 8.8 | 47 | NO | YES |
CVE-2005-2277HIGH Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command | Jul 15, 2005 | 10.0 | 41 | NO | YES |
CVE-2021-31932CRITICAL Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web p | Feb 11, 2022 | 9.8 | 40 | NO | NO |
CVE-2011-0498HIGH Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and pos | Jan 20, 2011 | 9.3 | 39 | NO | YES |
CVE-2009-0734HIGH Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file | Feb 25, 2009 | 9.3 | 35 | NO | YES |
CVE-2009-0649HIGH The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) via JavaScript code that calls the setAttributeNode method. | Feb 20, 2009 | 7.8 | 35 | NO | YES |
CVE-2005-2250HIGH Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share. | Jul 13, 2005 | 7.5 | 34 | NO | YES |
CVE-2025-7406HIGH Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root pri | Jun 30, 2026 | 7.8 | 33 | NO | NO |
CVE-2025-24815HIGH Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to | Jun 30, 2026 | 7.8 | 32 | NO | NO |
CVE-2025-27020CRITICAL Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system
.
This issue affects | Dec 8, 2025 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (150 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nokia.
Media articles that mention a CVE ID that affects a product developed by Nokia — matched by CVE ID, not by vendor name.