CVE-2025-26488: Improper input validation in XML Management service in Infinera MTC-9
Improper Input Validation vulnerability in Infinera MTC-9 allows remote unauthenticated users to crash the service and cause a reboot of the appliance, thus causing a DoS condition, via crafted XML payloads.This issue affects MTC-9: from R22.1.1.0275 before R23.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26488?
CVE-2025-26488 is classified as a denial of service (DoS) vulnerability that can crash the service and require a reboot of the Infinera MTC-9 appliance.
How do I fix CVE-2025-26488?
To mitigate CVE-2025-26488, upgrade Infinera MTC-9 to a version after R23.0.
Who is affected by CVE-2025-26488?
Users of Infinera MTC-9 running versions from R22.1.1.0275 up to, but not including, R23.0 are affected by CVE-2025-26488.
What can exploit CVE-2025-26488?
CVE-2025-26488 can be exploited by remote unauthenticated users through crafted XML payloads.
What are the consequences of CVE-2025-26488?
The consequences of CVE-2025-26488 include a potential denial of service condition that disrupts normal operations of the Infinera MTC-9 appliance.