Junglewise Threat Intelligence

CVE-2025-24816: Nokia MantaRay improper access control in API

CVE-2025-24816 · Severity: info · Published 2026-06-30

Technologies: Nokia MantaRay NM. Vendors: Nokia.

Executive brief

Nokia MantaRay, a network management solution, contains a security flaw in its programming interface. An authorized user could exploit this weakness to access sensitive or confidential information that they are not normally permitted to see. This could lead to the exposure of internal system data or configuration details beyond the user's intended role.

Technical details

An improper access control vulnerability exists in the Nokia MantaRay NM API due to insufficient authorization checks. An authenticated attacker with network access to the API can exploit this flaw to bypass intended permission restrictions. Successful exploitation allows the retrieval of confidential information that should be restricted based on the user's assigned privileges. The issue is addressed in version 25R2-NM and later.

Affected products

  • Nokia MantaRay NM <25R2-NM

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory

References

Related threats