Nozomi Networks CMC和Nozomi Networks Guardian都是美国Nozomi Networks公司的产品。Nozomi Networks CMC是一款网络管理平台。Nozomi Networks Guardian是一款防护软件。 Nozomi Networks CMC和Nozomi Networks Guardian存在跨站脚本漏洞,该漏洞源于对输入参数验证不当导致的存储型HTML注入问题,允许具有管理权限的认证用户创建用户名包含HTML标签的恶意用户,当受害者尝试删除包含
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Nozomi Networks | CMC | < 26.1.0 |
affected |
| Nozomi Networks | Guardian | < 26.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nozomi Networks | Guardian | 0 ~ 26.1.0 | - |
|
| Nozomi Networks | CMC | 0 ~ 26.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-40904 | 6.5 MEDIUM | HTML injection in Smart Polling in Guardian/CMC before 26.1.0 |
| CVE-2025-40901 | 5.9 MEDIUM | HTML injection in Credentials Manager in Guardian/CMC before 26.1.0 |
| CVE-2025-40903 | 5.9 MEDIUM | HTML injection in Schedule Restore Archive in Guardian/CMC before 26.1.0 |
| CVE-2025-40900 | 4.6 MEDIUM | Angular template injection in Reports in Guardian/CMC before 26.1.0 |
No comments yet