CVE-2025-24815

HIGH

Nokia MantaRay NM < 25R2-NM - Authenticated Unrestricted File Upload

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-24815. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2025-24815, an unrestricted file upload vulnerability in Nokia MantaRay NM. The code includes placeholder methods (`check` and `run`) but lacks actual exploit implementation, referencing only a TODO for PoC development.

Description

Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to upload malicious files onto the system.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2025-24815_nokia_mantaray.py

This repository contains an auto-generated stub module for CVE-2025-24815, an unrestricted file upload vulnerability in Nokia MantaRay NM. The code includes placeholder methods (`check` and `run`) but lacks actual exploit implementation, referencing only a TODO for PoC development.

Classification
Stub 99%
Attack Type
Other
Complexity
Moderate
Reliability
Theoretical
Target: Nokia MantaRay NM
Auth required
Prerequisites: Authenticated access to the target system · Network connectivity to the vulnerable service (default port 80/443)
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 1.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (3)
Nokia/MantaRay NM <25R2-NM
Nokia/MantaRay NM ≥25R2-NM
nokia/mantaray_nm < 25R2-NM
Published Jun 30, 2026
Tracked Since Jun 30, 2026