Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin)…
cve CVE-2025-7406 1 source, 1 claim · Watch
NVD writes:
Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts. the claim
Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts. the claim
- Severity
- HIGH NVD
- CVSS
- 7.8 NVD
- Vendor
- Nokia NVD
- Product
- MantaRay NM NVD
- CWE
- CWE-269 NVD
How far exploitation has got
- No public code known
- Proof of concept
- Proof of concept, verified
- A Metasploit module
- Exploited in the wild
- Used in ransomware campaigns
Timeline
| 2026-06-30 | first spoke of it: Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts. | NVD |
Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts.
What it is to other things
| affects | nokia/mantaray_nm NVD |
| made_by | nokia NVD |
Every value, with what each source said and its receipt
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Automatable automatable | NVD | no At least one of those steps needs a person. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MantaRay NM",
"vendor": "Nokia",
"versions": [
{
"status": "affected",
"version": "<NM 25R1-NM"
},
{
"status": "unaffected",
"version": "≥NM 25R1-NM"
}
]
}
],
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nokia:mantaray_nm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B6443BC-E253-42E1-83CD-E681CBE3F6BE",
"versionEndExcluding": "25R2-NM",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts."
},
{
"lang": "es",
"value": "Nokia MantaRay NM es vulnerable a una vulnerabilidad de escalada de privilegios de sudo donde un atacante local que posee privilegios administrativos (administrador local) puede escalar a privilegios de root completos en el host. La explotación exitosa resulta en acceso a nivel de root al sistema de archivos y la capacidad de ejecutar acciones como root. El riesgo puede mitigarse temporalmente restringiendo el conjunto de comandos permitidos a través de sudo para las cuentas afectadas."
}
],
"id": "CVE-2025-7406",
"lastModified": "2026-09-29T19:10:00.160",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-7406",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-30T13:31:19.958711Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-30T10:16:33.720",
"references": [
{
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"tags": [
"Vendor Advisory"
],
"url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-7406/"
}
],
"sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-269"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS cvss | NVD | 7.8receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MantaRay NM",
"vendor": "Nokia",
"versions": [
{
"status": "affected",
"version": "<NM 25R1-NM"
},
{
"status": "unaffected",
"version": "≥NM 25R1-NM"
}
]
}
],
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nokia:mantaray_nm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B6443BC-E253-42E1-83CD-E681CBE3F6BE",
"versionEndExcluding": "25R2-NM",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts."
},
{
"lang": "es",
"value": "Nokia MantaRay NM es vulnerable a una vulnerabilidad de escalada de privilegios de sudo donde un atacante local que posee privilegios administrativos (administrador local) puede escalar a privilegios de root completos en el host. La explotación exitosa resulta en acceso a nivel de root al sistema de archivos y la capacidad de ejecutar acciones como root. El riesgo puede mitigarse temporalmente restringiendo el conjunto de comandos permitidos a través de sudo para las cuentas afectadas."
}
],
"id": "CVE-2025-7406",
"lastModified": "2026-09-29T19:10:00.160",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-7406",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-30T13:31:19.958711Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-30T10:16:33.720",
"references": [
{
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"tags": [
"Vendor Advisory"
],
"url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-7406/"
}
],
"sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-269"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS vector cvss_vector | NVD | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:Hreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MantaRay NM",
"vendor": "Nokia",
"versions": [
{
"status": "affected",
"version": "<NM 25R1-NM"
},
{
"status": "unaffected",
"version": "≥NM 25R1-NM"
}
]
}
],
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nokia:mantaray_nm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B6443BC-E253-42E1-83CD-E681CBE3F6BE",
"versionEndExcluding": "25R2-NM",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts."
},
{
"lang": "es",
"value": "Nokia MantaRay NM es vulnerable a una vulnerabilidad de escalada de privilegios de sudo donde un atacante local que posee privilegios administrativos (administrador local) puede escalar a privilegios de root completos en el host. La explotación exitosa resulta en acceso a nivel de root al sistema de archivos y la capacidad de ejecutar acciones como root. El riesgo puede mitigarse temporalmente restringiendo el conjunto de comandos permitidos a través de sudo para las cuentas afectadas."
}
],
"id": "CVE-2025-7406",
"lastModified": "2026-09-29T19:10:00.160",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-7406",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-30T13:31:19.958711Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-30T10:16:33.720",
"references": [
{
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"tags": [
"Vendor Advisory"
],
"url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-7406/"
}
],
"sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-269"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| CWE cwe | NVD | CWE-269receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MantaRay NM",
"vendor": "Nokia",
"versions": [
{
"status": "affected",
"version": "<NM 25R1-NM"
},
{
"status": "unaffected",
"version": "≥NM 25R1-NM"
}
]
}
],
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nokia:mantaray_nm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B6443BC-E253-42E1-83CD-E681CBE3F6BE",
"versionEndExcluding": "25R2-NM",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts."
},
{
"lang": "es",
"value": "Nokia MantaRay NM es vulnerable a una vulnerabilidad de escalada de privilegios de sudo donde un atacante local que posee privilegios administrativos (administrador local) puede escalar a privilegios de root completos en el host. La explotación exitosa resulta en acceso a nivel de root al sistema de archivos y la capacidad de ejecutar acciones como root. El riesgo puede mitigarse temporalmente restringiendo el conjunto de comandos permitidos a través de sudo para las cuentas afectadas."
}
],
"id": "CVE-2025-7406",
"lastModified": "2026-09-29T19:10:00.160",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-7406",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-30T13:31:19.958711Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-30T10:16:33.720",
"references": [
{
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"tags": [
"Vendor Advisory"
],
"url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-7406/"
}
],
"sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-269"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Exploitation exploitation | NVD | none No evidence of exploitation, and no public proof of concept. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MantaRay NM",
"vendor": "Nokia",
"versions": [
{
"status": "affected",
"version": "<NM 25R1-NM"
},
{
"status": "unaffected",
"version": "≥NM 25R1-NM"
}
]
}
],
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nokia:mantaray_nm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B6443BC-E253-42E1-83CD-E681CBE3F6BE",
"versionEndExcluding": "25R2-NM",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts."
},
{
"lang": "es",
"value": "Nokia MantaRay NM es vulnerable a una vulnerabilidad de escalada de privilegios de sudo donde un atacante local que posee privilegios administrativos (administrador local) puede escalar a privilegios de root completos en el host. La explotación exitosa resulta en acceso a nivel de root al sistema de archivos y la capacidad de ejecutar acciones como root. El riesgo puede mitigarse temporalmente restringiendo el conjunto de comandos permitidos a través de sudo para las cuentas afectadas."
}
],
"id": "CVE-2025-7406",
"lastModified": "2026-09-29T19:10:00.160",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-7406",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-30T13:31:19.958711Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-30T10:16:33.720",
"references": [
{
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"tags": [
"Vendor Advisory"
],
"url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-7406/"
}
],
"sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-269"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Product product | NVD | MantaRay NMreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MantaRay NM",
"vendor": "Nokia",
"versions": [
{
"status": "affected",
"version": "<NM 25R1-NM"
},
{
"status": "unaffected",
"version": "≥NM 25R1-NM"
}
]
}
],
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nokia:mantaray_nm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B6443BC-E253-42E1-83CD-E681CBE3F6BE",
"versionEndExcluding": "25R2-NM",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts."
},
{
"lang": "es",
"value": "Nokia MantaRay NM es vulnerable a una vulnerabilidad de escalada de privilegios de sudo donde un atacante local que posee privilegios administrativos (administrador local) puede escalar a privilegios de root completos en el host. La explotación exitosa resulta en acceso a nivel de root al sistema de archivos y la capacidad de ejecutar acciones como root. El riesgo puede mitigarse temporalmente restringiendo el conjunto de comandos permitidos a través de sudo para las cuentas afectadas."
}
],
"id": "CVE-2025-7406",
"lastModified": "2026-09-29T19:10:00.160",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-7406",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-30T13:31:19.958711Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-30T10:16:33.720",
"references": [
{
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"tags": [
"Vendor Advisory"
],
"url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-7406/"
}
],
"sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-269"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity | NVD | HIGH From 7.0 to 8.9. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MantaRay NM",
"vendor": "Nokia",
"versions": [
{
"status": "affected",
"version": "<NM 25R1-NM"
},
{
"status": "unaffected",
"version": "≥NM 25R1-NM"
}
]
}
],
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nokia:mantaray_nm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B6443BC-E253-42E1-83CD-E681CBE3F6BE",
"versionEndExcluding": "25R2-NM",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts."
},
{
"lang": "es",
"value": "Nokia MantaRay NM es vulnerable a una vulnerabilidad de escalada de privilegios de sudo donde un atacante local que posee privilegios administrativos (administrador local) puede escalar a privilegios de root completos en el host. La explotación exitosa resulta en acceso a nivel de root al sistema de archivos y la capacidad de ejecutar acciones como root. El riesgo puede mitigarse temporalmente restringiendo el conjunto de comandos permitidos a través de sudo para las cuentas afectadas."
}
],
"id": "CVE-2025-7406",
"lastModified": "2026-09-29T19:10:00.160",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-7406",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-30T13:31:19.958711Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-30T10:16:33.720",
"references": [
{
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"tags": [
"Vendor Advisory"
],
"url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-7406/"
}
],
"sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-269"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | high | ||||
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MantaRay NM",
"vendor": "Nokia",
"versions": [
{
"status": "affected",
"version": "<NM 25R1-NM"
},
{
"status": "unaffected",
"version": "≥NM 25R1-NM"
}
]
}
],
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nokia:mantaray_nm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B6443BC-E253-42E1-83CD-E681CBE3F6BE",
"versionEndExcluding": "25R2-NM",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts."
},
{
"lang": "es",
"value": "Nokia MantaRay NM es vulnerable a una vulnerabilidad de escalada de privilegios de sudo donde un atacante local que posee privilegios administrativos (administrador local) puede escalar a privilegios de root completos en el host. La explotación exitosa resulta en acceso a nivel de root al sistema de archivos y la capacidad de ejecutar acciones como root. El riesgo puede mitigarse temporalmente restringiendo el conjunto de comandos permitidos a través de sudo para las cuentas afectadas."
}
],
"id": "CVE-2025-7406",
"lastModified": "2026-09-29T19:10:00.160",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-7406",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-30T13:31:19.958711Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-30T10:16:33.720",
"references": [
{
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"tags": [
"Vendor Advisory"
],
"url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-7406/"
}
],
"sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-269"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Technical impact technical_impact | NVD | total The attacker gains full control of the component, or all of its information. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MantaRay NM",
"vendor": "Nokia",
"versions": [
{
"status": "affected",
"version": "<NM 25R1-NM"
},
{
"status": "unaffected",
"version": "≥NM 25R1-NM"
}
]
}
],
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nokia:mantaray_nm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B6443BC-E253-42E1-83CD-E681CBE3F6BE",
"versionEndExcluding": "25R2-NM",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts."
},
{
"lang": "es",
"value": "Nokia MantaRay NM es vulnerable a una vulnerabilidad de escalada de privilegios de sudo donde un atacante local que posee privilegios administrativos (administrador local) puede escalar a privilegios de root completos en el host. La explotación exitosa resulta en acceso a nivel de root al sistema de archivos y la capacidad de ejecutar acciones como root. El riesgo puede mitigarse temporalmente restringiendo el conjunto de comandos permitidos a través de sudo para las cuentas afectadas."
}
],
"id": "CVE-2025-7406",
"lastModified": "2026-09-29T19:10:00.160",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-7406",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-30T13:31:19.958711Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-30T10:16:33.720",
"references": [
{
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"tags": [
"Vendor Advisory"
],
"url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-7406/"
}
],
"sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-269"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | Nokiareceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "MantaRay NM",
"vendor": "Nokia",
"versions": [
{
"status": "affected",
"version": "<NM 25R1-NM"
},
{
"status": "unaffected",
"version": "≥NM 25R1-NM"
}
]
}
],
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nokia:mantaray_nm:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8B6443BC-E253-42E1-83CD-E681CBE3F6BE",
"versionEndExcluding": "25R2-NM",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts."
},
{
"lang": "es",
"value": "Nokia MantaRay NM es vulnerable a una vulnerabilidad de escalada de privilegios de sudo donde un atacante local que posee privilegios administrativos (administrador local) puede escalar a privilegios de root completos en el host. La explotación exitosa resulta en acceso a nivel de root al sistema de archivos y la capacidad de ejecutar acciones como root. El riesgo puede mitigarse temporalmente restringiendo el conjunto de comandos permitidos a través de sudo para las cuentas afectadas."
}
],
"id": "CVE-2025-7406",
"lastModified": "2026-09-29T19:10:00.160",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9,
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-7406",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-30T13:31:19.958711Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-06-30T10:16:33.720",
"references": [
{
"source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"tags": [
"Vendor Advisory"
],
"url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-7406/"
}
],
"sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-269"
}
],
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary"
}
]
}
} | — |
Every claim, by kind
vulnerability
| Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root privileges on the host. Successful exploitation results in root-level access to the filesystem and the ability to execute actions as root. The risk can be temporarily mitigated by restricting the set of commands permitted via sudo for the affected accounts. zetlyn/cve-nvd · 2026-06-30 | automatable no cvss 7.8 cvss_vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H cwe CWE-269 exploitation none product MantaRay NM severity HIGH status Analyzed technical_impact total vendor Nokia | source |