Junglewise Threat Intelligence

CVE-2025-10262: Nokia SR Linux privilege escalation via unsanitized format validation

CVE-2025-10262 · Severity: info · Published 2026-06-16

Vendors: Nokia.

Executive brief

Nokia SR Linux, an operating system used in data center network switches, contains a security flaw that allows a user with limited access to gain full administrative control. By exploiting a weakness in how the system validates certain data formats, an attacker who is already logged into the device can execute restricted commands as a superuser. This could lead to a complete compromise of the network device, allowing the attacker to intercept traffic, modify configurations, or disrupt network operations.

Technical details

A local privilege escalation vulnerability exists in Nokia SR Linux due to improper input validation, specifically described as unsanitized format validation. An authenticated attacker with local access to the system can exploit this flaw to bypass security restrictions and execute arbitrary commands with root/superuser privileges. The root cause appears to be a failure to properly sanitize input used in format-related functions or validation routines. While the specific software versions are not listed in the summary, users are advised to consult Nokia's security advisory for patch information.

Affected products

  • Nokia SR Linux

Timeline

  • 2026-06-16: advisory: NVD published the CVE record based on Nokia's disclosure.

References

Related threats