CVE-2025-0980: Nokia Sr Linux

Medium severity, CVSS 6.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service. When exploited, an invalid validation allows JSON RPC access without providing valid authentication credentials.

Affected products

  • Nokia Sr Linux: before 23.10.6 (fixed in 23.10.6); before 24.10.2 (fixed in 24.10.2)

Published 2026-01-07. Last modified 2026-06-17.