CVE-2025-27019: Remote shell service (RSH) in Infinera MTC-9
Published Dec 8, 2025
·Updated
Remote shell service (RSH) in Infinera MTC-9 version R22.1.1.0275 allows an attacker to utilize password-less user accounts and obtain system access by activating a reverse shell.This issue affects MTC-9: from R22.1.1.0275 before R23.0.
Affected Software
3 affected components
Infinera MTC-9>=R22.1.1.0275<R23.0
All of the following
Nokia Infinera Mtc-9 Firmware>=22.1.1.0275<23.0
Nokia Infinera Mtc-9
Event History
Dec 8, 2025
CVE Published
via MITRE·09:22 AM
Data Sourced
via MITRE·09:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27019?
CVE-2025-27019 has a critical severity level due to the potential for unauthorized system access.
2
How do I fix CVE-2025-27019?
To fix CVE-2025-27019, update Infinera MTC-9 to version R23.0 or later.
3
What systems are affected by CVE-2025-27019?
CVE-2025-27019 affects Infinera MTC-9 versions from R22.1.1.0275 up to but not including R23.0.
4
What type of attack does CVE-2025-27019 enable?
CVE-2025-27019 enables an attacker to exploit password-less user accounts for unauthorized access via a reverse shell.
5
Does CVE-2025-27019 require user interaction to exploit?
Exploitation of CVE-2025-27019 does not require user interaction, making it particularly dangerous.