Junglewise Threat Intelligence

CVE-2025-40901: Nozomi Networks Guardian and CMC HTML injection in Credentials Manager

CVE-2025-40901 · Severity: medium · CVSS 5.9 · Published 2026-05-19

Technologies: Nozomi Networks Inc. Guardian.

Executive brief

A security vulnerability exists in the Credentials Manager of Nozomi Networks Guardian and CMC, which are platforms used to monitor and secure industrial and OT networks. An administrative user can save malicious code that triggers when another user attempts to delete a specific identity. This could be used to perform phishing attacks or redirect users to malicious websites, though existing security controls prevent full system takeover or direct data theft.

Technical details

A Stored HTML Injection vulnerability (CWE-79) exists in the Credentials Manager functionality of Nozomi Networks Guardian and CMC due to improper validation of input parameters. An authenticated attacker with administrative privileges can define a malicious identity containing arbitrary HTML tags. The payload is executed in the victim's browser when they attempt to delete the affected identity. While the existing Content Security Policy (CSP) and input validation prevent full Cross-Site Scripting (XSS) and direct information disclosure, the flaw enables phishing and open redirect attacks. The issue is resolved in version 26.1.0.

Affected products

  • Nozomi Networks Inc. Guardian < 26.1.0
  • Nozomi Networks Inc. Central Management Console (CMC) < 26.1.0

Timeline

  • 2026-05-19: disclosed: Initial advisory release by Nozomi Networks
  • 2026-05-19: patched: Fixed in version 26.1.0

References