Executive brief
Nokia MantaRay NM, a network management solution, contains a security flaw that allows users to upload unauthorized files. An attacker with valid login credentials could exploit this to place malicious software on the system. This could lead to a compromise of the management platform and potentially impact the stability of the managed network infrastructure.
Technical details
An unrestricted file upload vulnerability exists in Nokia MantaRay NM due to insufficient validation of file types during the upload process. An authenticated attacker can exploit this flaw by uploading arbitrary files, potentially including malicious scripts or executables, to the server. The vulnerability is reachable over the network but requires valid authentication credentials. If the uploaded files are stored in a web-accessible directory or executed by the system, it could lead to remote code execution (RCE). The issue is addressed in version 25R2-NM and later.
Affected products
- Nokia MantaRay NM < 25R2-NM
Timeline
- 2026-06-30: advisory: NVD publication date
- 2026-06-30: patched: Version 25R2-NM listed as unaffected