CVE-2025-40893 is a Stored HTML Injection vulnerability affecting Nozomi Networks CMC and Guardian products. An unauthenticated attacker can inject HTML tags into asset attributes by sending specially crafted network packets, which then render in a victim's browser when viewing the Asset List. This medium-severity vulnerability (CVSS 6.1) could lead to phishing or open redirect attacks, though full XSS and direct information disclosure are mitigated by existing security controls. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 25.5.0CPE matchmatch criteria | cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:* | ||
< 25.5.0CPE matchmatch criteria | cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.