CVE-2024-25660: Nokia Transcend Network Management System

Critical severity, CVSS 9.0. EPSS: 0.6% chance of exploitation in the next 30 days.

The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with unnecessary privileges.

Affected products

  • Nokia Transcend Network Management System: version 19.10.3 only

Published 2024-10-01. Last modified 2026-06-17.