CVE-2025-40901 Details
Description
A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious identity containing HTML tags. When a victim attempts to delete the affected identity, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.
A stored HTML injection vulnerability has been identified in the Credentials Manager feature of Nozomi Networks Guardian and CMC versions prior to 26.1.0. This vulnerability arises from inadequate validation of input parameters, allowing an authenticated user with administrative rights to create a malicious identity embedded with HTML tags. When another user attempts to delete this identity, the injected HTML is executed in their browser, potentially leading to phishing attacks and open redirects. Although full cross-site scripting exploitation and direct information disclosure are blocked by current input validation and Content Security Policy settings, the vulnerability still poses significant risks.
Users are advised to upgrade to version 26.1.0 or later. Nozomi customers should also review and manage administrative access and stored identities in the Credentials Manager.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-827968.html | siemens-SADP | |
| https://security.nozominetworks.com/NN-2026:4-01 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nozominetworks cmc | < 26.1.0 |
CPE
Remediation
| |
| nozominetworks guardian | < 26.1.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| Jun 9, 2026 | CVE Modified | siemens-SADP |
| May 19, 2026 | Initial Analysis | [email protected] |
| May 19, 2026 | New CVE Received | [email protected] |