CVE-2025-27020: Improper configuration of SSH service in Infinera MTC-9
Published Dec 8, 2025
·Updated
Improper configuration of the SSH service in Infinera MTC-9 allows an unauthenticated attacker to execute arbitrary commands and access data on file system
.
This issue affects MTC-9: from R22.1.1.0275 before R23.0.
Affected Software
3 affected components
Infinera MTC-9>=R22.1.1.0275<R23.0
All of the following
Nokia Infinera Mtc-9 Firmware>=22.1.1.0275<23.0
Nokia Infinera Mtc-9
Event History
Dec 8, 2025
CVE Published
via MITRE·09:26 AM
Data Sourced
via MITRE·09:26 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27020?
CVE-2025-27020 has been classified as a high severity vulnerability due to its potential for unauthorized command execution.
2
How do I fix CVE-2025-27020?
To mitigate CVE-2025-27020, update Infinera MTC-9 to version R23.0 or later immediately.
3
Who is affected by CVE-2025-27020?
CVE-2025-27020 affects users of Infinera MTC-9 running versions from R22.1.1.0275 up to, but not including, R23.0.
4
What type of attacks does CVE-2025-27020 enable?
CVE-2025-27020 allows unauthenticated attackers to execute arbitrary commands and access filesystem data.
5
What product is involved in CVE-2025-27020?
CVE-2025-27020 specifically involves the Infinera MTC-9 product line.