Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2025-40890 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

A Stored Cross-Site Scripting vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated low-privilege user can craft a malicious dashboard containing a JavaScript payload and share it with victim users, or a victim can be socially engineered to import a malicious dashboard template. When the victim views or imports the dashboard, the XSS executes in their browser context, allowing the attacker to perform unauthorized actions as the victim, such as modify application data, disrupt application availability, and access limited sensitive information.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')[email protected]

Affected Products

ProductVersions
Nozomi Networks Guardian
< 25.4.0 (semver)

CPE

  • cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:*

Remediation

  • Upgrade: 25.4.0moderate effort
  • Mitigation:low effort

    Use internal firewall features to limit access to the web management interface. Review all accounts with access to it and delete unnecessary ones.

Nozomi Networks CMC
< 25.4.0 (semver)

CPE

  • cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:*

Remediation

  • Upgrade: 25.4.0moderate effort
  • Mitigation:low effort

    Use internal firewall features to limit access to the web management interface. Review all accounts with access to it and delete unnecessary ones.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2025-40890
NVD Published Date:
Nov 25, 2025
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2025-40890 Details - Not Deferred