PT-2025-26855 · Microsens · Microsens Nmp Web+
Noam Moshe
+1
·
Published
2025-06-24
·
Updated
2025-07-17
·
CVE-2025-49151
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions:
MICROSENS NMP Web+ versions prior to 3.3.0
Description:
The issue allows an unauthenticated attacker to generate forged JSON Web Tokens (JWT) to bypass authentication. This could potentially lead to full system control. Organizations worldwide remain at risk.
Recommendations:
For versions prior to 3.3.0, update to version 3.3.0 to fix the issue. As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation. Avoid using the
JWT token in authentication processes until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microsens Nmp Web+