CVE-2021-26596: Nokia Netact

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.

Affected products

  • Nokia Netact: version 18a only

Published 2021-03-25. Last modified 2026-06-17.