PT-2025-26855 · Microsens · Microsens Nmp Web+

Noam Moshe

+1

·

Published

2025-06-24

·

Updated

2025-07-17

·

CVE-2025-49151

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions: MICROSENS NMP Web+ versions prior to 3.3.0
Description: The issue allows an unauthenticated attacker to generate forged JSON Web Tokens (JWT) to bypass authentication. This could potentially lead to full system control. Organizations worldwide remain at risk.
Recommendations: For versions prior to 3.3.0, update to version 3.3.0 to fix the issue. As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation. Avoid using the JWT token in authentication processes until the issue is resolved.

Fix

Weakness Enumeration

Related Identifiers

BDU:2026-00294
CVE-2025-49151

Affected Products

Microsens Nmp Web+