CVE-2025-27259: Ericsson Network Manager: improper neutralization of user controlled input
Published Oct 13, 2025
·Updated
Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims to other sites or domains.
Affected Software
2 affected components
Ericsson Network Manager<25.2
Ericsson Network Manager<25.2
Event History
Oct 13, 2025
CVE Published
via MITRE·06:16 AM
Data Sourced
via MITRE·06:16 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Jan 23, 57776
Event
via NVD·02:52 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-27259?
The severity of CVE-2025-27259 is classified as high due to the potential for data exfiltration and redirection of users.
2
How do I fix CVE-2025-27259?
To fix CVE-2025-27259, upgrade to Ericsson Network Manager version 25.2 or later.
3
What are the potential impacts of CVE-2025-27259?
The potential impacts of CVE-2025-27259 include unauthorized data access and phishing attacks through redirection.
4
Which versions of Ericsson Network Manager are affected by CVE-2025-27259?
Ericsson Network Manager versions prior to 25.2 GA are affected by CVE-2025-27259.
5
Is there a workaround for CVE-2025-27259?
There are no official workarounds for CVE-2025-27259; updating to the latest version is the recommended solution.