PatchSiren cyber security CVE debrief
CVE-2025-49151 Microsens CVE debrief
CVE-2025-49151 is a critical authentication-bypass issue in MICROSENS NMP Web+. CISA’s advisory says an unauthenticated attacker could generate forged JSON Web Tokens (JWTs) to bypass authentication. The affected product set is MICROSENS NMP Web+ version 3.2.5 and earlier, and MICROSENS recommends upgrading to version 3.3.0 for Windows and Linux.
- Vendor
- Microsens
- Product
- NMP Web+
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-24
- Original CVE updated
- 2025-06-24
- Advisory published
- 2025-06-24
- Advisory updated
- 2025-06-24
Who should care
MICROSENS NMP Web+ administrators, OT/ICS operators, and security teams responsible for the product’s web management environment, especially where version 3.2.5 or earlier is deployed.
Technical summary
The CISA CSAF advisory (ICSA-25-175-07) describes a network-reachable authentication bypass in MICROSENS NMP Web+ caused by forged JWTs. The affected product entry is MICROSENS NMP Web+: <=3.2.5. The published CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, which corresponds to a 9.1 critical severity. Remediation in the advisory points to MICROSENS NMP Web+ version 3.3.0 for Windows and Linux.
Defensive priority
Immediate. The issue requires no privileges or user interaction and can lead to authentication bypass, so affected systems should be prioritized for urgent upgrade and temporary access restriction until patched.
Recommended defensive actions
- Upgrade MICROSENS NMP Web+ to version 3.3.0 for Windows and Linux, as recommended in the advisory.
- Identify every deployment running MICROSENS NMP Web+ version 3.2.5 or earlier and confirm whether the management interface is exposed beyond trusted admin networks.
- Restrict access to the NMP Web+ interface to trusted administrative paths only until remediation is complete.
- Review authentication and administrative activity for unexpected successful sessions or configuration changes around the advisory period.
- Apply CISA industrial control system recommended practices and defense-in-depth guidance to reduce exposure of management services.
Evidence notes
The supplied CISA CSAF source (ICSA-25-175-07) states: affected product MICROSENS NMP Web+: <=3.2.5; vulnerability impact: unauthenticated attackers could generate forged JWTs to bypass authentication; remediation: update to NMP Web+ 3.3.0 for Windows and Linux. The advisory was initially published on 2025-06-24 with no later revision present in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-49151 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-49151
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-49151 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-49151
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-175-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-175-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.