IM
IronMonkey Threat Research

CVE-2025-40893 MEDIUM

Published: 2025-12-18 | Last Modified: 2026-04-14 | Status: Modified

Description

A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the affected assets in the Asset List (and similar functions), the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.

CVSS Metrics

Base Score: 6.1 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeCHANGED
Confidentiality ImpactLOW
Integrity ImpactLOW
Availability ImpactNONE

Source: [email protected]

Type: Secondary

Exploitability Score: 2.8

Impact Score: 2.7

Base Score: 5.3 (MEDIUM)

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack VectorNETWORK
Attack ComplexityLOW
Attack RequirementsNONE
Privileges RequiredNONE
User InteractionPASSIVE
Vulnerability ConfidentialityNONE
Vulnerability IntegrityLOW
Vulnerability AvailabilityNONE
Subsequent ConfidentialityLOW
Subsequent IntegrityLOW
Subsequent AvailabilityNONE

Source: [email protected]

Type: Secondary

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-79

Affected Products

Vendor Product Version Update Type
nozominetworks cmc * <built-in method update of dict object at 0x7d1ea39fd4c0> Application
nozominetworks guardian * <built-in method update of dict object at 0x7d1ea39fd080> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:*
Notification
Message here