CVE-2025-40895

MEDIUM

Nozomi Networks CMC < 25.6.0 - Authenticated Stored HTML Injection in Sensor Map

Title source: llm
STIX 2.1

Description

A Stored HTML Injection vulnerability was discovered in the CMC's Sensor Map functionality due to improper validation on connected Guardians' properties. A malicious authenticated user with administrator privileges on a Guardian connected to a CMC can edit the Guardian's properties to inject HTML tags. If the Sensor Map functionality is enabled in the CMC, when a victim CMC user interacts with it, then the injected HTML may render in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.

References (1)

Core 1
Core References

Scores

CVSS v3 4.8
EPSS 0.0018
EPSS Percentile 7.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
nozominetworks/cmc < 25.6.0
Published Mar 04, 2026
Tracked Since Mar 04, 2026