CVE-2025-40889

Severity CVSS v4.0:
HIGH
Type:
CWE-22 Path Traversal
Publication date:
07/10/2025
Last modified:
09/10/2025

Description

A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, by issuing a specifically-crafted request, can potentially alter the structure and content of files in the /data folder, and/or affect their availability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:* 25.2.0 (excluding)
cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:* 25.2.0 (excluding)


References to Advisories, Solutions, and Tools