remote unauthenticated users to gain access to other network resources
using HTTPS requests through the appliance used as a bridge.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.cvcn.gov.it/cvcn/cve/CVE-2025-26487 |
|
Mon, 22 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nokia
Nokia infinera Mtc-9 Nokia infinera Mtc-9 Firmware |
|
| CPEs | cpe:2.3:h:nokia:infinera_mtc-9:-:*:*:*:*:*:*:* cpe:2.3:o:nokia:infinera_mtc-9_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Nokia
Nokia infinera Mtc-9 Nokia infinera Mtc-9 Firmware |
Tue, 09 Dec 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Infinera
Infinera mtc-9 |
|
| Vendors & Products |
Infinera
Infinera mtc-9 |
Mon, 08 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 08 Dec 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows Server Side Request Forgery. | Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows remote unauthenticated users to gain access to other network resources using HTTPS requests through the appliance used as a bridge. |
Mon, 08 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-Side Request Forgery (SSRF) vulnerability in Infinera MTC-9 version allows Server Side Request Forgery. | |
| Title | Server Side Request Forgery (SSRF) in the web server of Infinera MTC-9 | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2025-12-08T17:46:01.623Z
Reserved: 2025-02-11T08:24:51.661Z
Link: CVE-2025-26487
Updated: 2025-12-08T17:45:58.287Z
Status : Analyzed
Published: 2025-12-08T09:15:46.487
Modified: 2025-12-22T18:56:07.003
Link: CVE-2025-26487
No data.
OpenCVE Enrichment
Updated: 2025-12-09T10:26:42Z