CVE-2025-40889
07.10.2025, 13:15
A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, by issuing a specifically-crafted request, can potentially alter the structure and content of files in the /data folder, and/or affect their availability.
| Vendor | Product | Version |
|---|---|---|
| nozominetworks | cmc | 𝑥 < 25.2.0 |
| nozominetworks | guardian | 𝑥 < 25.2.0 |
𝑥
= Vulnerable software versions