MEDIUM

CVE-2025-9912

2026-06-16 CVSS v3.1
CVSS
6.3

Description

Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.

Summary dbcve.org

Nokia SR Linux contains a local privilege escalation vulnerability that allows an authenticated user to execute arbitrary commands with superuser (root) privileges. The vulnerability likely involves improper validation or bypass of privilege separation mechanisms, enabling a standard user to escalate to root access.

Mitigation

Apply vendor-supplied patches for CVE-2025-9912 when available; until then, restrict administrative access to trusted personnel only and monitor for unusual command execution patterns.

Weakness (CWE)

CWE-269 Improper Privilege Management

EPSS Score

0.11%
Probability of exploitation in next 30 days
1.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE