CVE-2025-26487: Server Side Request Forgery (SSRF) in the web server of Infinera MTC-9
Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resources using HTTPS requests through the appliance used as a bridge.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26487?
CVE-2025-26487 is classified as a medium severity Server-Side Request Forgery (SSRF) vulnerability.
How do I fix CVE-2025-26487?
To fix CVE-2025-26487, ensure that you update Infinera MTC-9 to the latest patched version provided by the vendor.
What types of attacks can CVE-2025-26487 enable?
CVE-2025-26487 can enable attackers to send unauthorized requests to internal services or external resources, potentially leading to data exposure.
Is my system affected by CVE-2025-26487?
If you are using Infinera MTC-9, your system may be affected by CVE-2025-26487.
What should I do if I cannot immediately patch CVE-2025-26487?
If immediate patching is not possible for CVE-2025-26487, consider implementing network segmentation and access controls to mitigate risk.