Stored HTML Injection Vulnerability in Asset List by Nozomi Networks
CVE-2025-40893

5.3MEDIUM

Key Information:

Vendor
CVE Published:
18 December 2025

What is CVE-2025-40893?

A vulnerability has been identified in the Asset List functionality, stemming from inadequate validation of incoming network traffic data. This flaw allows malicious actors to send tailored network packets that inject HTML tags into asset attributes. When users interact with the affected assets in the Asset List, the injected HTML content is rendered in their browsers. This exploitation can lead to phishing attempts and potential open redirect attacks. Although existing input validation measures and Content Security Policy setups partially mitigate risks of full XSS exploitation and direct data disclosure, the vulnerability remains a concern for user safety.

Affected Version(s)

CMC 0 < 25.5.0

Guardian 0 < 25.5.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found by Stefano Libero of Nozomi Networks Product Security team during an internal investigation.
.
CVE-2025-40893 : Stored HTML Injection Vulnerability in Asset List by Nozomi Networks