External risk intelligence

Infinera MTC-9 SSH Command Execution Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-27020

The vulnerability affects the SSH service on Infinera MTC-9, a network hardware device. While SSH can be exposed to the internet, these management interfaces are typically intended for internal administrative access, protected by network controls, and are not designed to be public-facing endpoints in standard deployment patterns.

Missing Authentication

Nokia Infinera Mtc 9 Firmware

22.1.1.0275 to before 23.0

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Infinera MTC-9 system, specifically related to its SSH service configuration. This issue allows unauthorized access and potential command execution, which could lead to data compromise. The primary concern at this time is to confirm if our organization utilizes the affected Infinera MTC-9 devices.

  • Unsecured SSH access allows unauthorized system control.
  • Leadership should recall it impacts network infrastructure.
  • Confirm if Infinera MTC-9 devices are in use.

Attack Path

How an attacker could exploit the issue

An attacker can exploit an improper configuration in the SSH service of Infinera MTC-9 devices to execute arbitrary commands and access sensitive data. This vulnerability, which does not require any authentication or user interaction, can lead to a complete compromise of the affected system.

  • No authentication needed to access.
  • Triggered by improperly configured SSH service.
  • Leads to arbitrary command execution and data access.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could execute arbitrary commands and access data on the file system of the Infinera MTC-9 when its SSH service is improperly configured.

  • System commands and file system data at risk.
  • Through an improperly configured SSH service.
  • Unauthorized access and data exposure.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Infinera MTC-9 SSH service vulnerability requires immediate attention from teams managing network infrastructure and vendor relationships. The first practical step is to identify all instances of the MTC-9, determine their network exposure and criticality, and locate the accountable owner. Subsequent actions will depend on this risk assessment, potentially involving vendor coordination for updates or implementing temporary network segmentation.

  • Network and Infrastructure Teams own remediation.
  • Verify MTC-9 exposure and business criticality.
  • Plan vendor engagement and targeted upgrades.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Infinera MTC-9?

The Infinera MTC-9 is a piece of network hardware. It functions as part of an infrastructure system that utilizes firmware to manage data and communications, and is typically maintained by network or infrastructure engineering teams.

What does CWE-306 mean for CVE-2025-27020?

CWE-306 refers to Missing Authentication for Critical Function. In this context, the SSH service in the Infinera MTC-9 does not properly verify the identity of someone trying to connect, allowing them to bypass security checks and gain unauthorized control.

How is CVE-2025-27020 triggered?

An attacker triggers this vulnerability by connecting directly to the improperly configured SSH service on the target device. It does not require valid login credentials or prior interaction with a legitimate user to execute commands or access file system data.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal notes that while the SSH service is the target, these interfaces are generally meant for internal management rather than public internet exposure. If your device is segmented away from the internet, the risk profile changes significantly.

What should I do first if I run Infinera MTC-9?

Begin by creating an inventory of all MTC-9 units in your environment. Once identified, confirm the specific firmware version installed to see if it falls within the affected range, and evaluate how these devices are positioned on your network.

References