CVE-2025-27026
Last modified
CVE-2025-27026 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. A missing double-check feature in the WebGUI for CLI deactivation in Infinera G42 version R6.1.3 allows an authenticated administrator to make other management interfaces unavailable via local and network interfaces. The CLI deactivation via the WebGUI does not only stop CLI interface but deactivates also Linux Shell, WebGUI and Physical Serial Console access. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A missing double-check feature in the WebGUI for CLI deactivation in Infinera G42 version R6.1.3 allows an authenticated administrator to make other management interfaces unavailable via local and network interfaces. The CLI deactivation via the WebGUI does not only stop CLI interface but deactivates also Linux Shell, WebGUI and Physical Serial Console access. No confirmation is asked at deactivation time. Loosing access to these services device administrators are at risk of completely loosing device control.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nokia | G42 Firmware | >= 6.1.3, < 8.0 |
References
- https://euvd.enisa.europa.eu/vulnerability/CVE-2025-27026Third Party Advisory
- https://www.cvcn.gov.it/cvcn/cve/CVE-2025-27026Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-27026?
How severe is CVE-2025-27026?
How do I fix CVE-2025-27026?
Are you affected by CVE-2025-27026?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
