VYPR
Unrated severityNVD Advisory· Published Oct 7, 2025· Updated Oct 7, 2025

Path traversal in Time Machine functionality in Guardian/CMC before 25.2.0

CVE-2025-40889

Description

A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, by issuing a specifically-crafted request, can potentially alter the structure and content of files in the /data folder, and/or affect their availability.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.