CVE-2025-26489: Improper input validation in Netconf service in Infinera MTC-9
Improper input validation in the Netconf service in Infinera MTC-9 allows remote authenticated users to crash the service and reboot the appliance, thus causing a DoS condition, via crafted XML payloads.This issue affects MTC-9: from R22.1.1.0275 before R23.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26489?
CVE-2025-26489 is rated as a high-severity vulnerability due to its potential to cause denial-of-service conditions.
Who is affected by CVE-2025-26489?
CVE-2025-26489 affects remote authenticated users of Infinera MTC-9 running versions from R22.1.1.0275 before R23.0.
How do I fix CVE-2025-26489?
To remediate CVE-2025-26489, upgrade Infinera MTC-9 to version R23.0 or later.
What is the impact of CVE-2025-26489?
CVE-2025-26489 can allow authenticated users to crash the service and reboot the appliance, leading to a denial of service.
Is a patch available for CVE-2025-26489?
Yes, a patch is available by upgrading to Infinera MTC-9 version R23.0 or later to mitigate CVE-2025-26489.