CVE-2024-25659: Nokia Transcend Network Management System

High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.

In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access files and directories outside the SFTP user home directory.

Affected products

  • Nokia Transcend Network Management System: version 19.10.3 only

Published 2024-10-01. Last modified 2026-06-17.