CVE-2025-3718
7.9Nozomi Networks · Guardian and CMC
A client-side path traversal vulnerability in the web management interface allows authenticated users to trigger Cross-Site Scripting (XSS) attacks.
Executive summary
A path traversal vulnerability in Nozomi Networks Guardian and CMC, rated at 7.9, allows authenticated users to execute malicious scripts via a crafted URL.
Vulnerability
This vulnerability is a client-side path traversal flaw caused by insufficient input validation in the web management interface, which can be leveraged by an authenticated user with limited privileges to perform a Cross-Site Scripting (XSS) attack against another authenticated victim.
Business impact
The exploitation of this vulnerability could lead to unauthorized script execution within the context of an authenticated user's browser session. This may result in session hijacking, unauthorized actions performed on behalf of the victim, or the exposure of sensitive management interface data. Given the 7.9 CVSS score, this represents a significant risk to the integrity and confidentiality of the administrative environment.
Remediation
Immediate Action: Upgrade both Nozomi Networks Guardian and CMC software to version 25.2.0 or later to resolve the underlying input validation deficiency.
Proactive Monitoring: Review web access logs for unusual URL structures or unexpected parameters being passed to the management interface.
Compensating Controls: Implement a strict Web Application Firewall (WAF) policy to filter malicious URL patterns and restrict access to the management interface to trusted internal networks only.
Exploitation status
Public Exploit Available: No — no confirmed public exploit exists.
Analyst recommendation
The vulnerability presents a moderate to high risk, particularly in environments where administrative sessions are frequent. Security teams should prioritize the upgrade to version 25.2.0 across all affected Guardian and CMC instances to eliminate the risk of XSS-based session compromise.
More Nozomi Networks CVEs
Sources
Originally found and disclosed by This issue was found by Stefano Libero and Andrea Palanca of Nozomi Networks Product Security team during an internal in, per the CVE Program record.