CVE-2025-49152

The affected products contain JSON Web Tokens (JWT) that do not expire, which could allow an attacker to gain access to the system.
CVSS

No CVSS.

Configurations

No configuration.

History

17 Jul 2025, 14:15

Type Values Removed Values Added
References
  • {'url': 'https://www.microsens.com/support/downloads/nmp/', 'source': 'ics-cert@hq.dhs.gov'}
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : unknown
Summary (en) MICROSENS NMP Web+ contain JSON Web Tokens (JWT) that do not expire, which could allow an attacker to gain access to the system. (en) The affected products contain JSON Web Tokens (JWT) that do not expire, which could allow an attacker to gain access to the system.

26 Jun 2025, 18:57

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-25 17:15

Updated : 2025-07-17 14:15


NVD link : CVE-2025-49152

Mitre link : CVE-2025-49152

CVE.ORG link : CVE-2025-49152


JSON object : View

Products Affected

No product.

CWE
CWE-613

Insufficient Session Expiration