CVE-2025-10262: An unsanitized format validation vulnerability in Nokia SR Linux
Nokia SR Linux is vulnerable to local privilege escalation vulnerability due to unsanitized format validation. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove sudo/root privileges from accounts that do not require them and enforce least-privilege for all authenticated users.
Nokia SR Linux - user account privileges superuser/sudo privileges for non-admin accounts = revoke or limit - Configuration
Disable or restrict local shell/console access for non-administrative accounts; permit shell access only where explicitly needed for operations.
Nokia SR Linux - authentication local shell/console access for non-admin users = disable if not required - Compensating control
Restrict access to device management interfaces and authentication endpoints to trusted IPs via firewall/ACLs and place management interfaces on isolated management networks.
- Operational
Audit all authenticated accounts, revoke unused or suspicious accounts, and review account privileges and sessions for signs of misuse prior to applying a vendor patch.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10262?
CVE-2025-10262 has a risk score of 52, indicating a moderate level of severity.
How do I fix CVE-2025-10262?
To mitigate CVE-2025-10262, ensure that your version of Nokia SR Linux is updated to the latest patched release.
What type of vulnerability is CVE-2025-10262?
CVE-2025-10262 is classified as a local privilege escalation vulnerability due to unsanitized format validation.
Who is affected by CVE-2025-10262?
Authenticated users of Nokia SR Linux are affected by CVE-2025-10262.
What could an attacker achieve by exploiting CVE-2025-10262?
An attacker exploiting CVE-2025-10262 could execute arbitrary commands with superuser privileges.