CVE-2025-27258
CVE-2025-27258 is a critical-severity vulnerability in Ericsson Network Manager with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-284.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- CVSS v4: 6.9
- EPSS exploit prediction: 0% (20th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-33966
- Weakness: CWE-284
- Affected product: Ericsson Network Manager
- Published:
- Last modified:
Description
Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.
Frequently asked questions
- What is CVE-2025-27258?
- Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.
- How severe is CVE-2025-27258?
- CVE-2025-27258 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2025-27258 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (20th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-27258?
- CVE-2025-27258 affects Ericsson Network Manager. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-27258?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2025-27258 have an EU (EUVD) identifier?
- Yes. CVE-2025-27258 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-33966.
- When was CVE-2025-27258 published?
- CVE-2025-27258 was published on 2025-10-13 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:ericsson:network_manager:*:*:*:*:*:*:*:*
More vulnerabilities in Ericsson Network Manager
- CVE-2023-39909 — High (CVSS 8.8): Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access…
- CVE-2024-25007 — High (CVSS 7.1): Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application…
- CVE-2022-46408 — Medium (CVSS 6.8): Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network…
- CVE-2021-28488 — Medium (CVSS 6.5): Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access…
- CVE-2025-27259 — Medium (CVSS 5.4): Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate…
- CVE-2021-32570 — Medium (CVSS 4.9): In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can…
All CVEs affecting Ericsson Network Manager →
Other CWE-284 (Improper Access Control) vulnerabilities
- CVE-2026-76607 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.3 - ???.
- CVE-2026-20315 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering…
- CVE-2026-70921 — Critical (CVSS 10.0): Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The…
- CVE-2026-66803 — Critical (CVSS 10.0): Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
- CVE-2026-58630 — Critical (CVSS 10.0): Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-60358 — Critical (CVSS 10.0): Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).…
Browse all CWE-284 (Improper Access Control) vulnerabilities →