CVE-2025-22245: Broadcom VMware Nsx

Medium severity, CVSS 5.9. EPSS: 0.3% chance of exploitation in the next 30 days.

VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation.

Affected products

  • Broadcom VMware Nsx: from 3.2, before 4.1.2.6 (fixed in 4.1.2.6); from 4.2.1, before 4.2.1.4 (fixed in 4.2.1.4); version 4.2.2 only
  • VMware Cloud Foundation: from 4.5, up to and including 5.2.1.2
  • VMware Telco Cloud Infrastructure: from 2.2, up to and including 3.0
  • VMware Telco Cloud Platform: from 3.0, up to and including 5.0

Published 2025-06-04. Last modified 2026-06-17.