CVE-2025-40898
EUVD-2025-20425818.12.2025, 14:15
A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths, altering the device configuration and/or affecting its availability.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nozominetworks | cmc | 𝑥 < 25.5.0 |
| nozominetworks | guardian | 𝑥 < 25.5.0 |
𝑥
= Vulnerable software versions