CVE-2025-27258: Ericsson Network Manager: escalation of privilege vulnerability
Published Oct 13, 2025
·Updated
Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.
Affected Software
2 affected components
Ericsson Network Manager<25.1 GA
Ericsson Network Manager<25.1
Event History
Oct 13, 2025
CVE Published
via MITRE·06:25 AM
Data Sourced
via MITRE·06:25 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27258?
CVE-2025-27258 is categorized as a critical vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2025-27258?
To fix CVE-2025-27258, upgrade Ericsson Network Manager to version 25.1 GA or later.
3
What is the impact of exploiting CVE-2025-27258?
Exploiting CVE-2025-27258 can lead to unauthorized access and escalation of privileges within the Ericsson Network Manager.
4
Which versions are affected by CVE-2025-27258?
CVE-2025-27258 affects all Ericsson Network Manager versions prior to 25.1 GA.
5
Who is affected by CVE-2025-27258?
Organizations using affected versions of Ericsson Network Manager may be vulnerable to CVE-2025-27258.