CVE-2025-3718
Last modified
CVE-2025-3718 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious URL which, if visited by an authenticated victim, leads to a Cross-Site Scripting (XSS) attack.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious URL which, if visited by an authenticated victim, leads to a Cross-Site Scripting (XSS) attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nozominetworks | Cmc | < 25.2.0 |
| Nozominetworks | Guardian | < 25.2.0 |
References
- https://security.nozominetworks.com/NN-2025:4-01Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-3718?
How severe is CVE-2025-3718?
How do I fix CVE-2025-3718?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-37174Authenticated arbitrary file write vulnerability exists in t…7.2
- CVE-2025-37175Arbitrary file upload vulnerability exists in the web-based …7.2
- CVE-2025-37176A command injection vulnerability in AOS-8 allows an authent…7.2
- CVE-2025-37177An arbitrary file deletion vulnerability has been identified…6.5
- CVE-2025-37178Multiple out-of-bounds read vulnerabilities were identified …7.5
- CVE-2025-37179Multiple out-of-bounds read vulnerabilities were identified …5.3
- CVE-2025-37181Vulnerabilities in the web-based management interface of Edg…7.2
- CVE-2025-37182Vulnerabilities in the web-based management interface of Edg…7.2
- CVE-2025-37183Vulnerabilities in the web-based management interface of Edg…7.2
- CVE-2025-37184A vulnerability exists in an Orchestrator service that could…9.8
- CVE-2025-37185Vulnerabilities in the web-based management interface of Edg…4.8
- CVE-2025-37186A local privilege-escalation vulnerability has been discover…7.8
Are you affected by CVE-2025-3718?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
