Stored HTML Injection in Alerted Nodes Dashboard by Nozomi Networks
CVE-2025-40894
What is CVE-2025-40894?
A vulnerability was identified in the Alerted Nodes Dashboard of Nozomi Networks due to inadequate input validation in an input parameter. Malicious authenticated users can exploit this flaw to inject HTML tags by modifying a node label. If alerts are generated for the compromised node, the injected HTML can be displayed in the browser of users accessing the dashboard, potentially leading to phishing attacks and open redirect exploits. While the risk of full XSS exploitation and direct information leakage is mitigated by existing input validation and Content Security Policy, the potential for deception through manipulated content remains a concern.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
CMC 0 < 25.6.0
Guardian 0 < 25.6.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
