CVE-2026-40465

Summary

NSP is vulnerable to an open redirect due to insufficient server-side validation of the URL (or redirect) parameter.

Affected Software

VendorProductVersion RangeStatus
NokiaNSP23.11affected
NokiaNSP24.4affected
NokiaNSP24.8affected
NokiaNSP24.11affected
NokiaNSP25.4affected
NokiaNSP25.8affected
NokiaNSP25.11affected
NokiaNSPNSP 24.11-SP15unaffected
NokiaNSPNSP 25.11-SP5unaffected
NokiaNSPNSP 26.4 and laterunaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References