Vulnerabilities (CVE)

Filtered by vendor Nokia Subscribe
Total 150 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-10258 1 Nokia 1 Infinera Dna 2026-06-17 N/A 6.3 MEDIUM
Infinera DNA is vulnerable to a time-based SQL injection vulnerability due to insufficient input validation, which may result in leaking of sensitive information.
CVE-2024-28813 1 Nokia 2 Hit 7300, Hit 7300 Firmware 2026-06-17 N/A 8.4 HIGH
An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activate remote SSH access to the appliance via an unexpected network interface.
CVE-2024-28812 1 Nokia 2 Hit 7300, Hit 7300 Firmware 2026-06-17 N/A 8.8 HIGH
An issue was discovered in Infinera hiT 7300 5.60.50. A hidden SSH service (on the local management network interface) with hardcoded credentials allows attackers to access the appliance operating system (with highest privileges) via an SSH connection.
CVE-2024-28811 1 Nokia 2 Hit 7300, Hit 7300 Firmware 2026-06-17 N/A 3.3 LOW
An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.
CVE-2024-28810 1 Nokia 2 Hit 7300, Hit 7300 Firmware 2026-06-17 N/A 6.6 MEDIUM
An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attacker to achieve loss of confidentiality by analyzing these files.
CVE-2024-28809 1 Nokia 2 Hit 7300, Hit 7300 Firmware 2026-06-17 N/A 8.8 HIGH
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials.
CVE-2024-28808 1 Nokia 2 Hit 7300, Hit 7300 Firmware 2026-06-17 N/A 2.7 LOW
An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by accessing undocumented web applications.
CVE-2024-28807 1 Nokia 2 Hit 7300, Hit 7300 Firmware 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest OS administrators to obtain various users' passwords by accessing memory dumps of the desktop application.
CVE-2024-25661 1 Nokia 1 Transcend Network Management System 2026-06-17 N/A 7.7 HIGH
In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators to obtain various users' passwords by reading memory dumps of the desktop application.
CVE-2024-25660 1 Nokia 1 Transcend Network Management System 2026-06-17 N/A 9.0 CRITICAL
The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.
CVE-2024-25659 1 Nokia 1 Transcend Network Management System 2026-06-17 N/A 7.2 HIGH
In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access files and directories outside the SFTP user home directory.
CVE-2024-25658 1 Nokia 1 Transcend Network Management System 2026-06-17 N/A 6.5 MEDIUM
Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or exported configuration files) to obtain SNMP users' usernames and passwords in cleartext.
CVE-2023-41376 1 Nokia 2 Service Router Linux, Service Router Operating System 2026-06-17 N/A 7.5 HIGH
Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attributes.
CVE-2023-41355 1 Nokia 2 G-040w-q, G-040w-q Firmware 2026-06-17 N/A 9.8 CRITICAL
Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information leaking.
CVE-2023-41354 1 Nokia 2 G-040w-q, G-040w-q Firmware 2026-06-17 N/A 4.0 MEDIUM
Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit this vulnerability by sending a crafted package, resulting in partially sensitive information exposed to an actor.
CVE-2023-41353 1 Nokia 2 G-040w-q, G-040w-q Firmware 2026-06-17 N/A 8.8 HIGH
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service.
CVE-2023-41352 1 Nokia 2 G-040w-q, G-040w-q Firmware 2026-06-17 N/A 7.2 HIGH
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.
CVE-2023-41351 1 Nokia 2 G-040w-q, G-040w-q Firmware 2026-06-17 N/A 9.8 CRITICAL
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.
CVE-2023-41350 1 Nokia 2 G-040w-q, G-040w-q Firmware 2026-06-17 N/A 7.5 HIGH
Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks.
CVE-2023-31044 1 Nokia 1 Impact Mobile 2026-06-17 N/A 2.0 LOW
An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate data fields that may attempt data exfiltration or other malicious activity when automatically executed by the spreadsheet software.