PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-49151 Microsens CVE debrief

CVE-2025-49151 is a critical authentication-bypass issue in MICROSENS NMP Web+. CISA’s advisory says an unauthenticated attacker could generate forged JSON Web Tokens (JWTs) to bypass authentication. The affected product set is MICROSENS NMP Web+ version 3.2.5 and earlier, and MICROSENS recommends upgrading to version 3.3.0 for Windows and Linux.

Vendor
Microsens
Product
NMP Web+
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2025-06-24
Original CVE updated
2025-06-24
Advisory published
2025-06-24
Advisory updated
2025-06-24

Who should care

MICROSENS NMP Web+ administrators, OT/ICS operators, and security teams responsible for the product’s web management environment, especially where version 3.2.5 or earlier is deployed.

Technical summary

The CISA CSAF advisory (ICSA-25-175-07) describes a network-reachable authentication bypass in MICROSENS NMP Web+ caused by forged JWTs. The affected product entry is MICROSENS NMP Web+: <=3.2.5. The published CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, which corresponds to a 9.1 critical severity. Remediation in the advisory points to MICROSENS NMP Web+ version 3.3.0 for Windows and Linux.

Defensive priority

Immediate. The issue requires no privileges or user interaction and can lead to authentication bypass, so affected systems should be prioritized for urgent upgrade and temporary access restriction until patched.

Recommended defensive actions

  • Upgrade MICROSENS NMP Web+ to version 3.3.0 for Windows and Linux, as recommended in the advisory.
  • Identify every deployment running MICROSENS NMP Web+ version 3.2.5 or earlier and confirm whether the management interface is exposed beyond trusted admin networks.
  • Restrict access to the NMP Web+ interface to trusted administrative paths only until remediation is complete.
  • Review authentication and administrative activity for unexpected successful sessions or configuration changes around the advisory period.
  • Apply CISA industrial control system recommended practices and defense-in-depth guidance to reduce exposure of management services.

Evidence notes

The supplied CISA CSAF source (ICSA-25-175-07) states: affected product MICROSENS NMP Web+: <=3.2.5; vulnerability impact: unauthenticated attackers could generate forged JWTs to bypass authentication; remediation: update to NMP Web+ 3.3.0 for Windows and Linux. The advisory was initially published on 2025-06-24 with no later revision present in the supplied corpus.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-49151 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-49151

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-49151 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-49151

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-175-07.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-175-07

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.