CVE-2025-9912: A local privilege escalation vulnerability in Nokia SR Linux

Published Jun 16, 2026
·
Updated

Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.

Affected Software

1 affected component
Nokia SR Linux

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Restrict access to Nokia SR Linux management interfaces and systems to trusted administrative hosts and networks using firewall rules, ACLs, or network segmentation to limit which authenticated users can reach the device.

  2. Compensating control

    Apply least-privilege for local accounts: disable or remove unused accounts, restrict interactive login to administrators only, and limit sudo/privilege escalation rights to only those users that require them.

  3. Operational

    Audit existing user accounts and privilege assignments on affected systems, review authentication logs for signs of suspicious activity or attempted privilege escalation, and investigate any anomalies. If compromise is suspected, rotate credentials for affected accounts and escalate incident response procedures as appropriate.

Event History

Jun 16, 2026
CVE Published
via MITRE·05:58 AM
Data Sourced
via MITRE·05:58 AM
Description
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-9912?

The severity of CVE-2025-9912 is classified as medium with a CVSS score of 6.3.

2

How can I fix CVE-2025-9912?

To address CVE-2025-9912, ensure that you update your Nokia SR Linux software to the latest version provided by Nokia that includes the relevant patches.

3

What does CVE-2025-9912 affect?

CVE-2025-9912 affects Nokia SR Linux, an operating system used in Nokia network devices.

4

What can attackers do with CVE-2025-9912?

An attacker who successfully exploits CVE-2025-9912 can execute arbitrary commands with superuser privileges on the affected system.

5

Who is impacted by CVE-2025-9912?

Authenticated users of Nokia SR Linux are impacted by CVE-2025-9912 if they can exploit this local privilege escalation vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203