MEDIUM 6.3

CVE-2025-9912: Nokia SR Linux Local Privilege Escalation

CVE-2025-9912 is a local privilege escalation flaw in Nokia SR Linux that allows an authenticated user with elevated privileges to execute arbitrary commands as root. The vulnerability requires local access and existing authentication—an insider or someone already on the system—but once triggered, can grant complete system control. This is not a remote attack vector; however, it does transform limited user accounts into fully privileged ones.

Source data · NVD / CISA · public domain

CVSS
3.1 · 6.3 MEDIUM · CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
Weaknesses (CWE)
CWE-269
Affected products
0 configuration(s)
Published / Modified
2026-06-16 / 2026-06-17

NVD description (verbatim)

Nokia SR Linux is vulnerable to a local privilege escalation vulnerability. Successful exploitation of this vulnerability may allow an authenticated user to execute arbitrary commands with superuser privilege.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

Nokia SR Linux contains an improper privilege management vulnerability (CWE-269) that fails to properly enforce privilege boundaries during command execution. An authenticated user with high privileges can bypass security controls to run arbitrary commands with superuser (root) permissions. The attack surface is local-only, requires no user interaction, and has low attack complexity—meaning the exploit method is straightforward once an attacker has access to the system with appropriate initial credentials.

Business impact

If exploited, an attacker could compromise the integrity and availability of Nokia SR Linux–based network infrastructure. Potential impacts include: unauthorized modification of routing configurations, disruption of network services, installation of persistent backdoors, exfiltration of sensitive network data, and lateral movement to other network devices. In carrier or enterprise environments relying on SR Linux for critical routing, this could translate to network outages or security breaches affecting downstream services.

Affected systems

This vulnerability affects Nokia SR Linux installations. The source data does not specify which versions are affected; consult the official Nokia security advisory and patch documentation to determine the precise version boundaries and whether your deployment falls within the vulnerable range.

Exploitability

Exploitation requires local access and valid authentication credentials with elevated privileges. An insider, compromised administrator account, or an attacker who has already gained initial system access could exploit this. The attack is not wormable or remotely triggerable via the network. However, the low attack complexity means that once an attacker meets the prerequisite conditions (local access and authenticated session), carrying out the exploit is relatively straightforward. The vulnerability is not reported to be actively exploited in the wild.

Remediation

Apply the security patch from Nokia as soon as possible. Verify the specific patch version applicable to your SR Linux installation by consulting the official Nokia security advisory. In the interim, restrict local system access to trusted administrators only, enforce strong authentication (MFA where available), monitor for unusual privilege escalation attempts, and audit user activity on affected systems.

Patch guidance

1. Review the official Nokia SR Linux security advisory to identify the patched version(s) applicable to your deployment. 2. Test the patch in a non-production environment first to ensure compatibility with your network configuration. 3. Schedule maintenance windows to apply patches to production systems. 4. Verify patch installation by confirming the running version matches the released patch build. 5. Monitor system logs for any anomalies following patch deployment.

Detection guidance

Monitor for: (1) Unexpected privilege escalation events in system audit logs, particularly commands run as root by non-root users. (2) Access patterns to sensitive system binaries or configuration files by users with high privileges attempting unusual operations. (3) Abnormal process execution chains originating from authenticated user sessions. (4) Failed and successful privilege boundary enforcement events. Enable comprehensive audit logging on SR Linux systems and correlate events with your SIEM to detect exploitation attempts. Look for deviations from baseline administrator behavior.

Why prioritize this

While rated MEDIUM severity, this vulnerability poses a direct threat to network infrastructure stability and security. The local-only nature and authentication requirement lower the immediate risk in externally-facing systems, but insider threats or compromised admin accounts are realistic scenarios in many organizations. Patch urgently for systems accessible to untrusted administrators or in environments with elevated insider risk. Defer by a few days only if you have strong access controls and comprehensive monitoring already in place.

Risk score, explained

The CVSS 3.1 score of 6.3 (MEDIUM) reflects: local attack vector (no remote exploitation), high privileges required as a prerequisite, low attack complexity once access is gained, limited confidentiality impact (some data readable), but high integrity and availability impact (configurations and services modifiable or disabled). This scoring appropriately captures the severity of command execution as root, tempered by the practical barrier of requiring prior authentication and local access.

Frequently asked questions

Does this vulnerability allow remote code execution?

No. The vulnerability is local-only and requires the attacker to already have valid authentication credentials and access to the SR Linux system. Remote attackers cannot exploit this directly over the network.

Who is at risk from this vulnerability?

Organizations running Nokia SR Linux are at risk, particularly those with: untrusted or compromised administrators, shared system access, or weak access controls. Single-tenant, well-governed environments with strong authentication and auditability have lower exposure.

Is there active exploit code or in-the-wild exploitation?

The source data does not indicate this vulnerability is currently being exploited in the wild or tracked on the KEV (Known Exploited Vulnerabilities) catalog. However, organizations should still patch promptly given the simplicity of exploitation once prerequisites are met.

What should I do while waiting for a patch?

Immediately audit who has elevated privileges on affected systems, enforce strong authentication (including MFA if available), restrict local access to trusted administrators only, and enable comprehensive audit logging to detect any exploitation attempts.

This analysis is provided for informational purposes and represents a technical interpretation of publicly available vulnerability data as of the publication date. Patch versions, affected product ranges, and remediation steps must be verified against the official Nokia SR Linux security advisory before deployment. SEC.co does not provide legal liability for actions taken based on this analysis. Organizations should conduct their own risk assessment aligned with their security posture, business criticality, and threat landscape. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).