5.8
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L
Description
A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious URL which, if visited by an authenticated victim, leads to a Cross-Site Scripting (XSS) attack.
Basic Information
ID
CVE-2025-3718
Source
Nozomi
Published
Oct 7, 2025 at 12:33
Modified
Oct 7, 2025 at 13:21
Affected Product
Vendor
Nozomi Networks
Product
Guardian
Affected Versions
Nozomi Networks Guardian 0
Nozomi Networks CMC 0
Nozomi Networks CMC 0