CVE-2025-40903 Details
Description
A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious restore schedule containing HTML tags. When a victim views the affected schedule, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.
A stored HTML injection vulnerability has been identified in the Schedule Restore Archive feature of Nozomi Networks Guardian and CMC versions prior to 26.1.0. This vulnerability arises from inadequate validation of an input parameter, allowing an authenticated user with administrative rights to create a malicious restore schedule that includes HTML tags. When another user views the schedule, the injected HTML is rendered in their browser, potentially leading to phishing attacks and open redirects. However, full exploitation of cross-site scripting and direct information disclosure is mitigated by existing input validation and Content Security Policy settings.
Users are advised to upgrade to version 26.1.0 or later. Additionally, it is recommended to use internal firewall features to restrict access to the web management interface and to review and remove unnecessary administrative accounts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-827968.html | siemens-SADP | |
| https://security.nozominetworks.com/NN-2026:6-01 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nozominetworks cmc | < 26.1.0 |
CPE
Remediation
| |
| nozominetworks guardian | < 26.1.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| Jun 9, 2026 | CVE Modified | siemens-SADP |
| May 19, 2026 | Initial Analysis | [email protected] |
| May 19, 2026 | New CVE Received | [email protected] |