CVE-2025-40898

HIGH

Nozomi Networks CMC/Guardian <25.5.0 Authenticated Path Traversal & Arbitrary File Write

Title source: llm
STIX 2.1

Description

A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths, altering the device configuration and/or affecting its availability.

References (2)

Core 2

Scores

CVSS v3 8.1
EPSS 0.0034
EPSS Percentile 25.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (4)
Nozomi Networks/CMC < 25.5.0
Nozomi Networks/Guardian < 25.5.0
nozominetworks/cmc < 25.5.0
nozominetworks/guardian < 25.5.0
Published Dec 18, 2025
Tracked Since Feb 18, 2026