NN-2025:17-01

HTML injection in Sensor Map in CMC before 25.6.0

Last update: 2026-03-04

Advisory IDNN-2025:17-01
TopicHTML injection in Sensor Map in CMC before 25.6.0
CWE ImpactCWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Issue date2026-03-04
AffectsCMC < v25.6.0
CVE Name(s)CVE-2025-40895
CVSS DetailsCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS Score2.0 (CVSS v4.0)
4.8 (CVSS v3.1)
CVE Risk LevelLow (CVSS v4.0)
Medium (CVSS v3.1)
Risk Level for Nozomi customersLow

Summary

A Stored HTML Injection vulnerability was discovered in the CMC's Sensor Map functionality due to improper validation on connected Guardians' properties.

Impact

A malicious authenticated user with administrator privileges on a Guardian connected to a CMC can edit the Guardian's properties to inject HTML tags. If the Sensor Map functionality is enabled in the CMC, when a victim CMC user interacts with it, then the injected HTML may render in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.

Affected Products

CMC < v25.6.0

Workarounds and Mitigations

N/A

Solutions

Upgrade to v25.6.0 or later.

Modification History

2026-03-04: Initial revision

Related Links

Acknowledgements

We thank the following parties for their efforts:

  • Stefano Libero of Nozomi Networks Product Security team for finding this issue during an internal investigation

Contact

Nozomi Networks Product Security team can be reached at prodsec@nozominetworks.com.
More contact details on the PSIRT page.