CVE-2025-40898

Severity CVSS v4.0:
HIGH
Type:
CWE-22 Path Traversal
Publication date:
18/12/2025
Last modified:
06/01/2026

Description

A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths, altering the device configuration and/or affecting its availability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:* 25.5.0 (excluding)
cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:* 25.5.0 (excluding)


References to Advisories, Solutions, and Tools