Skip to content
Noroxi

Nokia records

153 published records for vendor nokia.

All records

153 records
  • Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass.

    CriticalCVSS 9.8No exploitEPSS 22%

    nokia · bts trs web consoleFeb 11, 2022

  • Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters i

    CriticalCVSS 10.0Proof of conceptEPSS 13%

    nokia · affixJul 15, 2005

  • Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vec

    CriticalCVSS 10.0No exploitEPSS 6%

    nokia · series 40Aug 8, 2008

  • Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and possibly later devices, allow remote attackers to execute arbit

    CriticalCVSS 10.0No exploitEPSS 6%

    nokia · series 40Aug 8, 2008

  • The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST re

    CriticalCVSS 9.8No exploitEPSS 5%

    nokia · i-240w-q gpon ont firmwareMar 5, 2019

  • The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST re

    HighCVSS 8.8Proof of conceptEPSS 18%

    nokia · i-240w-q gpon ont firmwareMar 5, 2019

  • In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.

    CriticalCVSS 9.8No exploitEPSS 2%

    nokia · 1350 optical management systemSep 13, 2022

  • The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH i

    CriticalCVSS 9.8No exploitEPSS 2%

    nokia · i-240w-q gpon ont firmwareMar 5, 2019

  • NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.

    CriticalCVSS 9.8No exploitEPSS 2%

    nokia · vitalsuiteJun 16, 2022

  • CVE-2011-0498
    39Monitor

    Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to c

    CriticalCVSS 9.3Proof of conceptEPSS 6%

    nokia · multimedia playerJan 20, 2011

  • CVE-2009-0734
    39Monitor

    Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code v

    CriticalCVSS 9.3Proof of conceptEPSS 5%

    nokia · nokia pc suiteFeb 25, 2009

  • Chunghwa Telecom NOKIA G-040W-Q - Broken Access Control

    CriticalCVSS 9.8No exploitEPSS 1%

    nokia · g-040w-q firmwareNov 3, 2023

  • Chunghwa Telecom NOKIA G-040W-Q - Excessive Authentication Attempts

    CriticalCVSS 9.8No exploitEPSS 1%

    nokia · g-040w-q firmwareNov 3, 2023

  • Chunghwa Telecom NOKIA G-040W-Q - Improper Input Validation

    CriticalCVSS 9.8No exploitEPSS 1%

    nokia · g-040w-q firmwareNov 3, 2023

  • Improper configuration of SSH service in Infinera MTC-9

    CriticalCVSS 9.8No exploitEPSS 1%

    nokia · infinera mtc-9 firmwareDec 8, 2025

  • Remote shell service (RSH) in Infinera MTC-9

    CriticalCVSS 9.8No exploitEPSS 0%

    nokia · infinera mtc-9 firmwareDec 8, 2025

  • CVE-2019-3920
    36Monitor

    The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP

    HighCVSS 8.8No exploitEPSS 4%

    nokia · i-240w-q gpon ont firmwareMar 5, 2019

  • CVE-2019-3919
    36Monitor

    The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent

    HighCVSS 8.8No exploitEPSS 4%

    nokia · i-240w-q gpon ont firmwareMar 5, 2019

  • Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.

    HighCVSS 8.8No exploitEPSS 3%

    nokia · impactNov 25, 2019

  • In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET par

    HighCVSS 8.8No exploitEPSS 2%

    nokia · network functions manager for transportDec 25, 2023

  • The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unautho

    CriticalCVSS 9.0No exploitEPSS 1%

    nokia · transcend network management systemOct 1, 2024

  • Insufficient Validation of Input in the URL

    CriticalCVSS 9.0No exploitEPSS 0%

    nokia · wavesuite nocJul 21, 2025

  • Access to local file system and its content

    CriticalCVSS 9.0No exploitEPSS 0%

    nokia · wavesuite nocJul 21, 2025

  • Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of

    HighCVSS 8.8No exploitEPSS 2%

    nokia · fastmile firmwareDec 27, 2021

  • In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.

    HighCVSS 8.8No exploitEPSS 1%

    nokia · 1350 optical management systemSep 13, 2022