CVE-2025-65885

MEDIUM
Published Dec 26, 2025 Modified Jan 9, 2026 CWE-77

Description

An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight v6.7), Nokia E7 (Delight v1.3), Nokia C7 (Delight v6.7), Nokia 700 (Delight v1.2), Nokia 701 (Delight v1.1), Nokia 603 (Delight v1.0), Nokia 500 (Delight v1.2), Nokia E6 (Delight v1.0), Nokia Oro (Delight v1.0), and Vertu Constellation T (Delight v1.0) allowing local attackers to inject startup scripts via crafted .txt files in the :\Data directory.

CVSS v3.1 Score

5.1
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Weakness Type (CWE)

CWE-77 CWE-77

Affected Products

Vendor Product
symwld delight_custom_firmware
nokia 808_pureview
symwld delight_custom_firmware
nokia c7
nokia n8
symwld delight_custom_firmware
nokia e7
symwld delight_custom_firmware
nokia 701
nokia c6-01
symwld delight_custom_firmware
nokia 500
nokia 700
symwld delight_custom_firmware
nokia 603
nokia e6
nokia oro
nokia vertu_constellation_t

References

Frequently Asked Questions

What is CVE-2025-65885? +
An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight v6.7), Nokia E7 (Delight v1.3), Nokia C7 (Delight v6.7), Nokia 700 (Delight v1.2), Nokia 701 (Delight v1.1), Nokia 603 (Delight v1.0), Nokia 500 (Delight v1.2), Nokia E6 (Delight v1.0), Nokia Oro (Delight v1.0), and Vertu Constellation T (Delight v1.0) allowing local attackers to inject startup scripts via crafted .txt files in the :\Data directory. It has a CVSS v3.1 base score of 5.1 (MEDIUM).
How severe is CVE-2025-65885? +
CVE-2025-65885 has a CVSS v3.1 score of 5.1 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2025-65885? +
CVE-2025-65885 affects products from nokia, symwld, specifically: 500, 603, 700, 701, 808_pureview, c6-01, c7, delight_custom_firmware, e6, e7, n8, oro, vertu_constellation_t. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-65885? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-65885 — free, no signup required.

Start Free Scan