CVE-2025-24819
A Relative Path Traversal vulnerability in Nokia MantaRay NM

Public disclosure

07-04-2026

Last updated

07-04-2026

Vulnerability type

Directory Traversal / Path Traversal

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVSS score

5.7

Description

Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Software Manager application.

Affected products and versions

All MantaRay NM versions earlier than 25R1-NM (exclusive).
 

Mitigation plan

Fixes have been provided in MantaRay NM 25R1-NM and later releases.

Acknowledgements

  • Andrea Carlo Maria Dattola (TIM S.p.A)
  • Cristina Coppola (TIM S.p.A)
  • Carlo Pannullo (TIM S.p.A)
  • Massimiliano Brolli (TIM S.p.A)

References