Junglewise Threat Intelligence

CVE-2025-40902: Nozomi Networks Guardian and CMC HTML injection in Users functionality

CVE-2025-40902 · Severity: medium · CVSS 5.9 · Published 2026-05-19

Technologies: Nozomi Networks Guardian, Nozomi Networks Central Management Console. Vendors: Nozomi Networks.

Executive brief

Nozomi Networks Guardian and CMC, which are used for industrial cybersecurity and network monitoring, are affected by a security flaw in their user management interface. An administrative user can create a specially crafted username that triggers malicious code in the browser of another administrator when they attempt to delete certain groups. While existing security measures prevent full system takeover, this could be used for phishing or redirecting staff to malicious websites.

Technical details

A stored HTML injection vulnerability exists in the Users functionality of Nozomi Networks Guardian and CMC due to improper validation of the username input parameter. An authenticated attacker with administrative privileges can create a user with a name containing HTML tags. This payload is executed in the context of another user's browser when they perform specific actions, such as attempting to delete a group containing the malicious user. While the platform's Content Security Policy (CSP) and existing input validation prevent full Cross-Site Scripting (XSS) and direct data exfiltration, the flaw can be leveraged for phishing or open redirect attacks. The issue is resolved in version 26.1.0.

Affected products

  • Nozomi Networks Guardian < 26.1.0
  • Nozomi Networks Central Management Console (CMC) < 26.1.0

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: patched: Fixed in version 26.1.0
  • 2026-05-19: advisory

References

Related threats