← console
voxell vciy

CVE-2025-24937: Access to local file system and its content

ROUTINE

Telemetry drift only. No threshold crossed and no authority ruling changed.

CVE record loaded 2026-09-20.

What to do now held facts and links

  1. Upgrade to WS-NOC 24.6 FP3 or later CVE record
  2. Record your decision, dated and frozen with today's evidence: patch by a date · mitigated by a compensating control · deferred · accepted the risk · not affected
  3. Check your version against the ranges this record publishes.

What it is stated by the CNA

File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web application and the container it is running on. The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. The web application allows arbitrary files to be included in a file that was downloadable and executable by the web server.

weakness
Not named by the CNA. NVD maps it to CWE-98.
affected
Nokia WaveSuite NOC
versions
Nokia WaveSuite NOC WS-NOC 24.6, WS-NOC 23.6 and WS-NOC 23.12
published ranges
nokia wavesuite noc 23.6; nokia wavesuite noc 23.12; nokia wavesuite noc 24.6
fixed in
WS-NOC 24.6 FP3
assigned by
Nokia
published
2025-07-21

check us nokia.com

Exploit code held, dated

exploit code
None held in the PoC-in-GitHub feed. A public repository changes this brief.

What moved held, dated

dateEPSSevent
21 Jul 20250.00018
24 Jul 20250.0003
27 Jul 20250.00035
11 Aug 20250.00041
22 Aug 20250.00071
20 Nov 20250.00056
17 Dec 20250.00027
29 Dec 20250.00032
14 Feb 20260.00036
24 Feb 20260.00034
26 Mar 20260.00038
16 Apr 20260.00042
17 May 20260.00114
15 Jun 20260.0023scoring model v2026.06.15
21 Jun 20260.0024
10 Aug 20260.00246

16 observations held. A step marked with a scoring model moved because the measurement was replaced, not because the vulnerability changed.

Outside the record researched, cited

This section reads the record's references and adds cited findings from outside it. It needs an account. Everything above is held facts and is complete without it.

Sign in to add the researched section

What would change this brief held, dated

CISA KEV
Not listed in the catalogue we hold. A listing changes this brief.
exploit probability
0.00 on 2026-08-10 (FIRST's EPSS, a probability and not evidence of exploitation). Next band line: 10% (0.10). Crossing a line changes this brief.
fix
Held: WS-NOC 24.6 FP3 (CVE record, loaded 2026-09-20). A newer fix from the CNA or OSV changes this brief.

Watch this CVE What counts as a move

How to check this

Every value above is held with two dates: when it was true upstream (as_of) and when we recorded it (tx_from). Re-derive the exploit probability as it stood on any date:

SELECT value, source, source_version, as_of, tx_from
FROM volatile_valid_as_of('CVE-2025-24937', '2026-10-03T23:59:59.999999Z', now());

Identity above is quoted from the CVE Program record, corpus cvelistv5_20260920, recorded 30 Sep 2026.