CVE-2023-25187

MEDIUM

Nokia Airscale ASIKA Firmware - Use of Hard-coded SSH Keys

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-25187. PoCs published by Amirhossein Bahramizadeh.

AI-analyzed exploit summary This exploit leverages a hard-coded private key in Nokia ASIKA 7.13.52 to establish an SSH connection and perform a man-in-the-middle (MITM) attack, forwarding data between the vulnerable device and an attacker-controlled SSH server.

Description

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time installed) default SSH public/private key values that are specific to a network operator. As a result, the CSP internal BTS network SSH server (disabled by default) continues to apply the default SSH public/private key values. These keys don't give access to BTS, because service user authentication is username/password-based on top of SSH. Nokia factory installed default SSH keys are meant to be changed from operator-specific values during the BTS deployment commissioning phase. However, before the 21B release, BTS commissioning manuals did not provide instructions to change default SSH keys (to BTS operator-specific values). This leads to a possibility for malicious operations staff (inside a CSP network) to attempt MITM exploitation of BTS service user access, during the moments that SSH is enabled for Nokia service personnel to perform troubleshooting activities.

Exploits (1)

exploitdb WORKING POC
by Amirhossein Bahramizadeh · cremotehardware
https://www.exploit-db.com/exploits/51535

This exploit leverages a hard-coded private key in Nokia ASIKA 7.13.52 to establish an SSH connection and perform a man-in-the-middle (MITM) attack, forwarding data between the vulnerable device and an attacker-controlled SSH server.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Nokia ASIKA 7.13.52
Auth required
Prerequisites: Network access to the vulnerable device · Knowledge of the hard-coded private key path · Attacker-controlled machine with SSH server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 6.3
EPSS 0.0018
EPSS Percentile 38.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (5)
nokia/asika_airscale_firmware 19b
nokia/asika_airscale_firmware 20a
nokia/asika_airscale_firmware 20b
nokia/asika_airscale_firmware 20c
nokia/asika_airscale_firmware 21a
Published Jun 16, 2023
Tracked Since Feb 18, 2026