Path Traversal Vulnerability in Time Machine Functionality by Nozomi Networks
CVE-2025-40889

7.2HIGH

Key Information:

Vendor
CVE Published:
7 October 2025

What is CVE-2025-40889?

A path traversal vulnerability has been identified within the Time Machine functionality of Nozomi Networks' product. This flaw results from inadequate validation of two input parameters, allowing authenticated users with limited privileges to issue crafted requests. As a consequence, attackers could manipulate the structure and content of files within the /data directory, potentially compromising the availability and integrity of those files.

Affected Version(s)

CMC 0 < 25.2.0

Guardian 0 < 25.2.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found by Andrea Palanca of Nozomi Networks Product Security team during an internal investigation.
.