CVE-2025-40890 Details
Description
A Stored Cross-Site Scripting vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated low-privilege user can craft a malicious dashboard containing a JavaScript payload and share it with victim users, or a victim can be socially engineered to import a malicious dashboard template. When the victim views or imports the dashboard, the XSS executes in their browser context, allowing the attacker to perform unauthorized actions as the victim, such as modify application data, disrupt application availability, and access limited sensitive information.
A stored cross-site scripting vulnerability has been identified in the Dashboards feature of Nozomi Networks Guardian and CMC versions prior to 25.4.0. This vulnerability arises from inadequate validation of input parameters, allowing authenticated low-privilege users to create malicious dashboards embedded with JavaScript payloads. These dashboards can be shared with other users or, alternatively, victims can be tricked into importing a harmful dashboard template. Once the dashboard is viewed or imported, the embedded script executes in the user's browser, enabling the attacker to perform unauthorized actions on behalf of the victim. This could include modifying application data, disrupting service availability, and accessing restricted sensitive information.
Users are advised to upgrade to Nozomi Networks Guardian or CMC version 25.4.0 or later. Additionally, it is recommended to use internal firewall features to restrict access to the web management interface and to review and remove unnecessary accounts with access to this interface.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 25, 2025CISA-ADP
Assessed Nov 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.nozominetworks.com/NN-2025:11-01 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Nozomi Networks Guardian | < 25.4.0 (semver) |
CPE
Remediation
| |
| Nozomi Networks CMC | < 25.4.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Nov 25, 2025 | New CVE Received | [email protected] |
Volerion