Executive brief
Nokia NSP is a network service platform used for managing and orchestrating telecom networks. The application is vulnerable to an open redirect attack due to insufficient validation of user-supplied URL parameters, which could allow attackers to redirect users to malicious external websites and potentially facilitate phishing or credential theft attacks.
Technical details
NSP contains an open redirect vulnerability in URL or redirect parameter handling due to insufficient server-side validation. The vulnerability allows attackers to craft malicious links containing attacker-controlled redirect destinations that are not properly validated before redirection. This is a network-accessible vulnerability requiring user interaction (clicking a malicious link). Attackers can exploit this to redirect users to external phishing sites or malware distribution points, potentially compromising user credentials or enabling social engineering attacks. Patches from Nokia should be consulted for remediation.
Affected products
- Nokia NSP
Timeline
- 2026-08-31: disclosed