PatchSiren cyber security CVE debrief
CVE-2025-49152 MICROSENS CVE debrief
CVE-2025-49152 is a HIGH-severity authentication/session-control issue in MICROSENS NMP Web+. According to CISA’s advisory, affected versions contain JSON Web Tokens that do not expire, which can allow an attacker to gain access to the system. MICROSENS recommends updating to NMP Web+ 3.3.0 for Windows and Linux.
- Vendor
- MICROSENS
- Product
- NMP Web+
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-24
- Original CVE updated
- 2025-06-24
- Advisory published
- 2025-06-24
- Advisory updated
- 2025-06-24
Who should care
Organizations running MICROSENS NMP Web+ in operational or industrial environments, especially administrators responsible for authentication, access control, and patch management.
Technical summary
The advisory identifies MICROSENS NMP Web+ <= 3.2.5 as affected. The core problem is that JWTs do not expire, so token validity is not properly time-limited. CISA assigns CVSS v3.1 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N), indicating a network-reachable issue with no privileges or user interaction required and a high integrity impact.
Defensive priority
High. This affects access control and can permit unauthorized system access; patching should be prioritized for exposed or operational deployments.
Recommended defensive actions
- Update MICROSENS NMP Web+ to version 3.3.0 for Windows and Linux as recommended by the vendor.
- Inventory all MICROSENS NMP Web+ deployments and confirm whether any instances are running version 3.2.5 or earlier.
- Review authentication and session-management controls for affected systems, including token handling and administrative access pathways.
- Restrict network exposure to NMP Web+ management interfaces until remediation is complete.
- After upgrading, verify that access tokens and sessions follow expected expiration and revocation behavior.
Evidence notes
CISA’s CSAF advisory ICSA-25-175-07, published 2025-06-24, states that MICROSENS NMP Web+ products at version <= 3.2.5 contain JSON Web Tokens (JWT) that do not expire and that this could allow an attacker to gain access to the system. The advisory’s remediation is to update to NMP Web+ version 3.3.0 for Windows and Linux. The supplied CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N with a score of 7.5 (HIGH).
Sources and references
Verified primary and authoritative sources
-
CVE-2025-49152 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-49152
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-49152 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-49152
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-175-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-175-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.