External risk intelligence

Infinera MTC-9 Remote Shell Vulnerability Enables System Access

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-27019

The vulnerability affects a Remote Shell (RSH) service on infrastructure hardware. While network-reachable, RSH is a legacy administrative protocol typically restricted to internal management networks or isolated out-of-band management segments. It is not designed to be exposed to the public internet in standard deployments.

Missing Authentication

Nokia Infinera Mtc 9 Firmware

22.1.1.0275 to before 23.0

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in network infrastructure equipment, specifically the Infinera MTC-9, that could allow unauthorized system access without credentials. The primary concern is confirming whether this specific equipment is deployed and exposed in a manner that presents a risk.

  • Unauthorized access to network equipment is possible.
  • Understand potential impact on network infrastructure.
  • Confirm relevance and exposure within our environment.

Attack Path

How an attacker could exploit the issue

An attacker could gain system access by exploiting a flaw in the remote shell service of the affected device. This allows an attacker to activate a reverse shell without needing any credentials, potentially leading to full system compromise.

  • Entry condition: No authentication required.
  • Trigger point: Activating the remote shell service.
  • Resulting risk: Full system access.

Live Threat

Current exploitation, exposure, and threat context

A critical vulnerability in the Infinera MTC-9's remote shell service could allow an unauthenticated attacker to gain system access. This occurs when password-less user accounts are utilized, enabling the activation of a reverse shell. When supported by the advisory, this could affect the integrity and availability of system operations.

  • System access and control.
  • Exploiting password-less accounts.
  • Unauthorized system modification or disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Infinera MTC-9 firmware's remote shell service is the affected technology, likely managed by infrastructure or network operations teams. The initial practical move is to identify all MTC-9 instances, confirm their network exposure and criticality, locate the responsible system owner, and then prioritize remediation based on risk assessment.

  • Infrastructure or network ops owns issue.
  • Verify MTC-9 network exposure and criticality.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Infinera MTC-9 and why is it used?

Infinera MTC-9 is a piece of network infrastructure hardware that uses specialized firmware to manage data communications. These devices serve as critical nodes in networking environments, often handling the routing and management of traffic flows. Because they sit deep within network architecture, they typically support remote administrative protocols like Remote Shell (RSH) to allow operators to manage and maintain device health from a distance.

What does CWE-306 mean for CVE-2025-27019?

This CVE is categorized under CWE-306, which refers to a Missing Authentication for Critical Function. In plain terms, this means the software allows someone to perform sensitive administrative actions—like executing commands or opening a remote shell—without first verifying who they are. Because the RSH service in this version does not check for credentials, it creates a path for unauthorized system access.

How can an attacker trigger this RSH vulnerability?

An attacker triggers this flaw by interacting with the device's remote shell service, which allows the activation of a reverse shell using existing password-less user accounts. It is important to note that the vulnerability relies on the presence of these specific unauthenticated accounts; if an account requires valid credentials or if the RSH service is disabled, the vulnerability cannot be activated through this specific path.

Do I need to worry if my Infinera MTC-9 is on an internal network?

While the vulnerability is severe, Halo Surface Signal notes that RSH is a legacy protocol typically reserved for isolated management segments or internal networks, not the public internet. If your device is correctly segmented away from public access, the risk is lower; however, you should still prioritize investigating the device configuration to ensure it is not inadvertently reachable from broader or untrusted network segments.

What should I do first to address this advisory?

Start by performing an inventory to locate all instances of the Infinera MTC-9 within your environment. Once you have a list, verify how each device is connected and whether the remote shell service is active. Work with the teams responsible for these devices to determine their network placement and prioritize updating the firmware to a version beyond the affected range, ensuring you move away from configurations that allow password-less access.

References