Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service. When exploited, an invalid validation allows JSON RPC access without providing valid authentication credentials.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 Jan 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux
Nokia
Nokia service Router Linux
Vendors & Products Linux
Linux linux
Nokia
Nokia service Router Linux

Wed, 07 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 Jan 2026 07:30:00 +0000

Type Values Removed Values Added
Description Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service. When exploited, an invalid validation allows JSON RPC access without providing valid authentication credentials.
Title JSON RPC authentication bypass in Nokia SR Linux
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Nokia

Published:

Updated: 2026-01-07T14:43:24.734Z

Reserved: 2025-02-03T08:49:28.343Z

Link: CVE-2025-0980

cve-icon Vulnrichment

Updated: 2026-01-07T14:31:05.621Z

cve-icon NVD

Status : Received

Published: 2026-01-07T12:16:45.973

Modified: 2026-01-07T15:15:42.417

Link: CVE-2025-0980

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-08T09:49:19Z

Weaknesses