CVE-2025-9974: Insufficient Input Validation on WEBUI in Nokia ONT/Beacon product
The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users to trigger unintended system-level command execution. Due to insufficient validation of user-supplied data, a low-privileged authenticated attacker may be able to execute arbitrary commands on the underlying ONT/Beacon operating system, potentially impacting the confidentiality, integrity, and availability of the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9974?
CVE-2025-9974 is categorized with a low severity due to its impact being limited to authenticated users.
How do I fix CVE-2025-9974?
To mitigate CVE-2025-9974, ensure that input validation mechanisms are properly implemented to sanitize user-supplied data.
Who is affected by CVE-2025-9974?
CVE-2025-9974 affects the Nokia ONT/Beacon product due to a vulnerability in its unified WEBUI application.
What type of vulnerability is CVE-2025-9974?
CVE-2025-9974 is an input handling flaw that allows unintended command execution.
Can CVE-2025-9974 be exploited remotely?
CVE-2025-9974 requires authentication, so it cannot be exploited by unauthenticated remote attackers.