CVE-2025-40902 Details
Description
A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete a group containing the affected user, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.
A stored HTML injection vulnerability has been identified in the Users functionality of Nozomi Networks Guardian and CMC versions prior to 26.1.0. This vulnerability arises from inadequate validation of input parameters, allowing an authenticated user with administrative privileges to create a user with a username that includes HTML tags. When another user attempts to delete a group containing the manipulated user, the injected HTML is executed in their browser. This could lead to phishing attacks and potentially allow open redirects. However, full exploitation of cross-site scripting and direct information disclosure is blocked by current input validation and Content Security Policy settings.
Users are advised to upgrade to version 26.1.0 or later. Additionally, it is recommended to use internal firewall features to restrict access to the web management interface, review accounts with administrative privileges, and delete any unnecessary accounts. Existing usernames should also be reviewed for potential exploitation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-827968.html | siemens-SADP | |
| https://security.nozominetworks.com/NN-2026:5-01 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nozominetworks cmc | < 26.1.0 |
CPE
Remediation
| |
| nozominetworks guardian | < 26.1.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| Jun 9, 2026 | CVE Modified | siemens-SADP |
| May 19, 2026 | Initial Analysis | [email protected] |
| May 19, 2026 | New CVE Received | [email protected] |