Stored HTML Injection in CMC's Sensor Map Functionality
CVE-2025-40895

2LOW

Key Information:

Status
Vendor
CVE Published:
4 March 2026

What is CVE-2025-40895?

A vulnerability within the CMC's Sensor Map functionality allows a malicious authenticated user with administrative privileges to inject harmful HTML tags by improperly validating connected Guardian properties. If the Sensor Map feature is active, this can result in the injected HTML being rendered in the browsers of other CMC users, potentially facilitating phishing attacks. While the existing input validation and Content Security Policy configurations inhibit full XSS exploitation and direct information disclosure, the vulnerability still poses significant risks to user interaction with the affected functionality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

CMC 0 < 25.6.0

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found by Stefano Libero of Nozomi Networks Product Security team during an internal investigation.
.