CVE-2025-24816

MEDIUM

Nokia MantaRay NM < 25R2-NM - Authenticated API Information Disclosure

Title source: manual
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-24816. PoCs published by HermesNA-1.

AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2025-24816, an Improper Access Control vulnerability in Nokia MantaRay's API. The code includes placeholder methods (`check` and `run`) but lacks actual exploit implementation, referencing only a Nokia advisory for details.

Description

Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assigned privileges.

Exploits (1)

github STUB 1 stars
by HermesNA-1 · pythonpoc
https://github.com/HermesNA-1/SnakeSploit/tree/main/data/modules_generated/cve-2025-24816_nokia_mantaray_subject.py

This repository contains an auto-generated stub module for CVE-2025-24816, an Improper Access Control vulnerability in Nokia MantaRay's API. The code includes placeholder methods (`check` and `run`) but lacks actual exploit implementation, referencing only a Nokia advisory for details.

Classification
Stub 99%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Theoretical
Target: Nokia MantaRay
Auth required
Prerequisites: Authenticated access to the target API · Network connectivity to the vulnerable Nokia MantaRay instance
mistral-large-3 · analyzed Jul 09, 2026 Full analysis →

Scores

CVSS v3 6.5
EPSS 0.0020
EPSS Percentile 10.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (3)
Nokia/MantaRay NM <25R2-NM
Nokia/MantaRay NM ≥25R2-NM
nokia/mantaray_nm < 25R2-NM
Published Jun 30, 2026
Tracked Since Jun 30, 2026