CVE-2025-40904
Modified Modified - Updated After Analysis
Stored HTML Injection in Smart Polling Feature

Publication date: 2026-05-19

Last updated on: 2026-06-09

Assigner: Nozomi Networks Inc.

Description
A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through the sync. When a victim views the affected remote strategy in the Smart Polling functionality, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-05-19
Last Modified
2026-06-09
Generated
2026-06-10
AI Q&A
2026-05-19
EPSS Evaluated
2026-06-08
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
nozominetworks cmc to 26.1.0 (exc)
nozominetworks guardian to 26.1.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2025-40904 is a Stored HTML Injection vulnerability found in the Smart Polling feature of Guardian and CMC software versions before 26.1.0. It occurs because of improper validation of an input parameter, which allows an authenticated user with limited privileges to inject malicious HTML tags through remote strategies.

When a victim views the affected remote strategy in the Smart Polling functionality, the injected HTML renders in their browser. This can enable phishing attacks or open redirect attacks. However, full cross-site scripting (XSS) exploitation and direct information disclosure are prevented by existing input validation and Content Security Policy configurations.

Impact Analysis

This vulnerability can impact you by allowing attackers with limited privileges to inject malicious HTML into remote strategies that other users view. When these users view the affected content, the malicious HTML can execute in their browsers, potentially leading to phishing attacks or open redirect attacks.

Although full XSS exploitation and direct information disclosure are prevented, the vulnerability still poses a medium risk and can compromise user trust and security.

Mitigation Strategies

To mitigate the Stored HTML Injection vulnerability in the Smart Polling feature, users are advised to upgrade their Guardian and CMC software to version 26.1.0 or later.

As a workaround, users can review and remove any untrusted sensors to reduce the risk of malicious HTML injection.

Compliance Impact

The provided information does not specify how the Stored HTML Injection vulnerability directly affects compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-40904. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart