CVE-2025-40893

MEDIUM

Nozomi Networks CMC and Guardian < 25.5.0 - Unauthenticated Stored HTML Injection in Asset List

Title source: llm
STIX 2.1

Description

A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the affected assets in the Asset List (and similar functions), the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.

Scores

CVSS v3 6.1
EPSS 0.0016
EPSS Percentile 5.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (4)
Nozomi Networks/CMC < 25.5.0
Nozomi Networks/Guardian < 25.5.0
nozominetworks/cmc < 25.5.0
nozominetworks/guardian < 25.5.0
Published Dec 18, 2025
Tracked Since Feb 18, 2026