CVE-2025-40889
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-07

Last updated on: 2025-10-09

Assigner: Nozomi Networks Inc.

Description
A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, by issuing a specifically-crafted request, can potentially alter the structure and content of files in the /data folder, and/or affect their availability.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-07
Last Modified
2025-10-09
Generated
2026-06-16
AI Q&A
2025-10-07
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
nozominetworks cmc to 25.2.0 (exc)
nozominetworks guardian to 25.2.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in the Time Machine functionality caused by missing validation of two input parameters. An authenticated user with limited privileges can send a specially crafted request to potentially modify the structure and content of files in the /data folder or affect their availability.

Impact Analysis

The vulnerability can allow an authenticated user with limited privileges to alter or disrupt files in the /data folder, potentially leading to data modification or denial of availability of those files.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-40889. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart