CVE-2025-24333 - CVE House
Back to Database
Status published Unknown CVE-2025-24333

Administrative user shell input validation fault

Vulnerability Description

Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, which authenticated admin user can, in theory, potentially use for injecting arbitrary commands for unprivileged baseband OAM service process execution via special characters added to baseband internal COMA_config.xml file. This issue has been corrected starting from release 24R1-SR 1.0 MP and later, by adding proper input validation to OAM service process which prevents injecting special characters via baseband internal COMA_config.xml file.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-24333

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Nokia Single RAN
Vulnerable Versions:
All the releases prior to 24R1-SR 1.0 MP, 24R1-SR 1.0 MP and later

Timeline

Official Publish: July 2nd, 2025
Last Modified: July 2nd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.