CVE-2025-49151CWE-547

Use of Hard-coded, Security-relevant Constants in MICROSENS NMP Web+

Critical · published June 25, 2025

CVSS v4.0
9.3
EPSS
1%
Percentile
44.7
In the wild
Unconfirmed
What it is

The affected products could allow an unauthenticated attacker to generate forged JSON Web Tokens (JWT) to bypass authentication.

The record
Technical detail
CVSS v4.0
9.3 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00562 · 44.7th percentile
Weakness
CWE-547 · Use of Hard-coded, Security-relevant Constants
Published
2025-06-25T16:32Z
EPSS history
Timeline
  • 25 JUN 16:32Z
    Use of Hard-coded, Security-relevant Constants in MICROSENS NMP Web+
    cvelistv5