High severity8.1NVD Advisory· Published Oct 7, 2025· Updated Jun 17, 2026
CVE-2025-40889
CVE-2025-40889
Description
A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, by issuing a specifically-crafted request, can potentially alter the structure and content of files in the /data folder, and/or affect their availability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:*range: <25.2.0
- (no CPE)range: 0
cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:*range: <25.2.0
- (no CPE)range: 0
Patches
Vulnerability mechanics
References
1- security.nozominetworks.com/NN-2025:9-01nvdVendor Advisory
News mentions
0No linked articles in our index yet.