Executive brief
Nozomi Networks Guardian and CMC appliances, which are used for industrial network monitoring and management, contain a security flaw in their Smart Polling feature. An attacker with low-level access can inject malicious HTML code into the system. If an administrator or another user views the affected page, they could be targeted with phishing content or redirected to malicious websites, potentially compromising their credentials or workstation.
Technical details
A stored HTML injection vulnerability exists in the Smart Polling functionality of Nozomi Networks Guardian and CMC due to improper validation of input parameters. An authenticated attacker with limited privileges can push malicious remote strategies containing HTML tags through the synchronization process. When a victim views these strategies, the injected HTML is rendered in their browser. While existing input validation and Content Security Policy (CSP) configurations prevent full Cross-Site Scripting (XSS) and direct information disclosure, the flaw still allows for phishing and open redirect attacks. The issue is fixed in version 26.1.0.
Affected products
- Nozomi Networks Guardian < 26.1.0
- Nozomi Networks Central Management Console (CMC) < 26.1.0
Timeline
- 2026-05-19: disclosed: Initial discovery by Nozomi Networks internal security team.
- 2026-05-19: advisory
- 2026-05-19: patched: Fixed in version 26.1.0.