CVE-2025-40891

MEDIUM

Nozomi Networks CMC and Guardian < 25.5.0 - Unauthenticated Stored HTML Injection via Time Machine Snapshot Diff

Title source: llm
STIX 2.1

Description

A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset attributes across two snapshots. Exploitation requires a victim to use the Time Machine Snapshot Diff feature on those specific snapshots and perform specific GUI actions, at which point the injected HTML renders in their browser, enabling phishing and open redirect attacks. Full XSS exploitation is prevented by input validation and Content Security Policy. Attack complexity is high due to multiple required conditions.

Scores

CVSS v3 4.7
EPSS 0.0014
EPSS Percentile 4.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (4)
Nozomi Networks/CMC < 25.5.0
Nozomi Networks/Guardian < 25.5.0
nozominetworks/cmc < 25.5.0
nozominetworks/guardian < 25.5.0
Published Dec 18, 2025
Tracked Since Feb 18, 2026