Nokia records
153 published records for vendor nokia.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 17
- With a fix record
- 9.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')10
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')10
- CWE-20 Improper Input Validation8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-312 Cleartext Storage of Sensitive Information5
The weakness classes this vendor ships most often: where to look.
CWEAll records
153 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2021-31932No exploit | Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass.nokia · bts trs web console | Critical9.8 | — | 21.6% | Feb 11, 2022 |
44Plan | CVE-2005-2277Proof of concept | Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters inokia · affix | Critical10.0 | — | 12.9% | Jul 15, 2005 |
42Plan | CVE-2008-3553No exploit | Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vecnokia · series 40 · CWE-264 | Critical10.0 | — | 5.9% | Aug 8, 2008 |
42Plan | CVE-2008-3552No exploit | Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and possibly later devices, allow remote attackers to execute arbitnokia · series 40 | Critical10.0 | — | 5.9% | Aug 8, 2008 |
41Plan | CVE-2019-3922No exploit | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST renokia · i-240w-q gpon ont firmware · CWE-121 | Critical9.8 | — | 5.2% | Mar 5, 2019 |
40Plan | CVE-2019-3921Proof of concept | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST renokia · i-240w-q gpon ont firmware · CWE-121 | High8.8 | — | 17.9% | Mar 5, 2019 |
40Plan | CVE-2022-39815No exploit | In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.nokia · 1350 optical management system · CWE-78 | Critical9.8 | — | 2.1% | Sep 13, 2022 |
40Plan | CVE-2019-3918No exploit | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH inokia · i-240w-q gpon ont firmware · CWE-798 | Critical9.8 | — | 2.0% | Mar 5, 2019 |
40Plan | CVE-2021-41487No exploit | NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.nokia · vitalsuite · CWE-89 | Critical9.8 | — | 1.8% | Jun 16, 2022 |
39Monitor | CVE-2011-0498Proof of concept | Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to cnokia · multimedia player · CWE-119 | Critical9.3 | — | 5.7% | Jan 20, 2011 |
39Monitor | CVE-2009-0734Proof of concept | Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code vnokia · nokia pc suite · CWE-119 | Critical9.3 | — | 5.1% | Feb 25, 2009 |
39Monitor | CVE-2023-41351No exploit | Chunghwa Telecom NOKIA G-040W-Q - Broken Access Controlnokia · g-040w-q firmware · CWE-288 | Critical9.8 | — | 0.8% | Nov 3, 2023 |
39Monitor | CVE-2023-41350No exploit | Chunghwa Telecom NOKIA G-040W-Q - Excessive Authentication Attemptsnokia · g-040w-q firmware · CWE-307 | Critical9.8 | — | 0.8% | Nov 3, 2023 |
39Monitor | CVE-2023-41355No exploit | Chunghwa Telecom NOKIA G-040W-Q - Improper Input Validationnokia · g-040w-q firmware · CWE-940 | Critical9.8 | — | 0.6% | Nov 3, 2023 |
39Monitor | CVE-2025-27020No exploit | Improper configuration of SSH service in Infinera MTC-9nokia · infinera mtc-9 firmware · CWE-306 | Critical9.8 | — | 0.5% | Dec 8, 2025 |
39Monitor | CVE-2025-27019No exploit | Remote shell service (RSH) in Infinera MTC-9nokia · infinera mtc-9 firmware · CWE-306 | Critical9.8 | — | 0.4% | Dec 8, 2025 |
36Monitor | CVE-2019-3920No exploit | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTPnokia · i-240w-q gpon ont firmware · CWE-78 | High8.8 | — | 3.9% | Mar 5, 2019 |
36Monitor | CVE-2019-3919No exploit | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent nokia · i-240w-q gpon ont firmware · CWE-78 | High8.8 | — | 3.9% | Mar 5, 2019 |
36Monitor | CVE-2019-17403No exploit | Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.nokia · impact · CWE-434 | High8.8 | — | 2.5% | Nov 25, 2019 |
36Monitor | CVE-2022-39818No exploit | In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parnokia · network functions manager for transport · CWE-78 | High8.8 | — | 2.2% | Dec 25, 2023 |
36Monitor | CVE-2024-25660No exploit | The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthonokia · transcend network management system · CWE-266 | Critical9.0 | — | 0.6% | Oct 1, 2024 |
36Monitor | CVE-2025-24936No exploit | Insufficient Validation of Input in the URLnokia · wavesuite noc · CWE-78 | Critical9.0 | — | 0.4% | Jul 21, 2025 |
36Monitor | CVE-2025-24937No exploit | Access to local file system and its contentnokia · wavesuite noc · CWE-98 | Critical9.0 | — | 0.2% | Jul 21, 2025 |
35Monitor | CVE-2021-45896No exploit | Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use ofnokia · fastmile firmware | High8.8 | — | 1.6% | Dec 27, 2021 |
35Monitor | CVE-2022-39819No exploit | In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.nokia · 1350 optical management system · CWE-78 | High8.8 | — | 1.5% | Sep 13, 2022 |
- CVE-2021-3193245Plan
Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass.
CriticalCVSS 9.8No exploitEPSS 22%nokia · bts trs web consoleFeb 11, 2022
- CVE-2005-227744Plan
Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters i
CriticalCVSS 10.0Proof of conceptEPSS 13%nokia · affixJul 15, 2005
- CVE-2008-355342Plan
Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vec
CriticalCVSS 10.0No exploitEPSS 6%nokia · series 40Aug 8, 2008
- CVE-2008-355242Plan
Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and possibly later devices, allow remote attackers to execute arbit
CriticalCVSS 10.0No exploitEPSS 6%nokia · series 40Aug 8, 2008
- CVE-2019-392241Plan
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST re
CriticalCVSS 9.8No exploitEPSS 5%nokia · i-240w-q gpon ont firmwareMar 5, 2019
- CVE-2019-392140Plan
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST re
HighCVSS 8.8Proof of conceptEPSS 18%nokia · i-240w-q gpon ont firmwareMar 5, 2019
- CVE-2022-3981540Plan
In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.
CriticalCVSS 9.8No exploitEPSS 2%nokia · 1350 optical management systemSep 13, 2022
- CVE-2019-391840Plan
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH i
CriticalCVSS 9.8No exploitEPSS 2%nokia · i-240w-q gpon ont firmwareMar 5, 2019
- CVE-2021-4148740Plan
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
CriticalCVSS 9.8No exploitEPSS 2%nokia · vitalsuiteJun 16, 2022
- CVE-2011-049839Monitor
Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to c
CriticalCVSS 9.3Proof of conceptEPSS 6%nokia · multimedia playerJan 20, 2011
- CVE-2009-073439Monitor
Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code v
CriticalCVSS 9.3Proof of conceptEPSS 5%nokia · nokia pc suiteFeb 25, 2009
- CVE-2023-4135139Monitor
Chunghwa Telecom NOKIA G-040W-Q - Broken Access Control
CriticalCVSS 9.8No exploitEPSS 1%nokia · g-040w-q firmwareNov 3, 2023
- CVE-2023-4135039Monitor
Chunghwa Telecom NOKIA G-040W-Q - Excessive Authentication Attempts
CriticalCVSS 9.8No exploitEPSS 1%nokia · g-040w-q firmwareNov 3, 2023
- CVE-2023-4135539Monitor
Chunghwa Telecom NOKIA G-040W-Q - Improper Input Validation
CriticalCVSS 9.8No exploitEPSS 1%nokia · g-040w-q firmwareNov 3, 2023
- CVE-2025-2702039Monitor
Improper configuration of SSH service in Infinera MTC-9
CriticalCVSS 9.8No exploitEPSS 1%nokia · infinera mtc-9 firmwareDec 8, 2025
- CVE-2025-2701939Monitor
Remote shell service (RSH) in Infinera MTC-9
CriticalCVSS 9.8No exploitEPSS 0%nokia · infinera mtc-9 firmwareDec 8, 2025
- CVE-2019-392036Monitor
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP
HighCVSS 8.8No exploitEPSS 4%nokia · i-240w-q gpon ont firmwareMar 5, 2019
- CVE-2019-391936Monitor
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent
HighCVSS 8.8No exploitEPSS 4%nokia · i-240w-q gpon ont firmwareMar 5, 2019
- CVE-2019-1740336Monitor
Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.
HighCVSS 8.8No exploitEPSS 3%nokia · impactNov 25, 2019
- CVE-2022-3981836Monitor
In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET par
HighCVSS 8.8No exploitEPSS 2%nokia · network functions manager for transportDec 25, 2023
- CVE-2024-2566036Monitor
The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unautho
CriticalCVSS 9.0No exploitEPSS 1%nokia · transcend network management systemOct 1, 2024
- CVE-2025-2493636Monitor
Insufficient Validation of Input in the URL
CriticalCVSS 9.0No exploitEPSS 0%nokia · wavesuite nocJul 21, 2025
- CVE-2025-2493736Monitor
Access to local file system and its content
CriticalCVSS 9.0No exploitEPSS 0%nokia · wavesuite nocJul 21, 2025
- CVE-2021-4589635Monitor
Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of
HighCVSS 8.8No exploitEPSS 2%nokia · fastmile firmwareDec 27, 2021
- CVE-2022-3981935Monitor
In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.
HighCVSS 8.8No exploitEPSS 1%nokia · 1350 optical management systemSep 13, 2022