Nozomi Networks Guardian and CMC Stored HTML Injection Vulnerability in Diagram Tab and Graph View

Vulnerability

A stored HTML injection vulnerability has been identified in Nozomi Networks Guardian and CMC versions prior to 26.2.0. This vulnerability arises in the Diagram tab and Graph view, where a shared input validation function fails to adequately restrict user input. An authenticated user with administrative privileges can exploit this by injecting malicious HTML tags into N2OS configuration data through various input vectors. When the affected data is viewed in the Diagram tab and Graph view, the injected HTML is rendered in the browser, potentially leading to phishing attacks and open redirects. However, full exploitation of cross-site scripting and direct information disclosure is mitigated by existing input validation and Content Security Policy configurations.

Impact

Exploitation allows for stored HTML injection, with the injected HTML rendered in the victim's browser. This could facilitate phishing attacks and open redirects, although full cross-site scripting exploitation and direct information disclosure are blocked by current input validation and Content Security Policy settings.

Remediation

Users are advised to upgrade to version 26.2.0 or later. Additionally, internal firewall features can be used to restrict access to the web management interface, and it is recommended to review and remove unnecessary administrative accounts.

Added: Jul 9, 2026, 8:33 AM
Updated: Jul 9, 2026, 8:33 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.2
exploitability
2.8
remediation
7.9
relevance
9.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.