Stored HTML Injection in Alerted Nodes Dashboard by Nozomi Networks
CVE-2025-40894

2.1LOW

Key Information:

Vendor
CVE Published:
4 March 2026

What is CVE-2025-40894?

A vulnerability was identified in the Alerted Nodes Dashboard of Nozomi Networks due to inadequate input validation in an input parameter. Malicious authenticated users can exploit this flaw to inject HTML tags by modifying a node label. If alerts are generated for the compromised node, the injected HTML can be displayed in the browser of users accessing the dashboard, potentially leading to phishing attacks and open redirect exploits. While the risk of full XSS exploitation and direct information leakage is mitigated by existing input validation and Content Security Policy, the potential for deception through manipulated content remains a concern.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CMC 0 < 25.6.0

Guardian 0 < 25.6.0

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found by Stefano Libero of Nozomi Networks Product Security team during an internal investigation.
.