Critical hijack vulnerabilities have been discovered in MICROSENS NMP Web+.
Initially reported on June 24, the trio of bugs stem from hard-coded, security-relevant constants (CVE-2025-49151), insufficient session expiration (CVE-2025-49152), and improper limitation of a pathname to a restricted directory (CVE-2025-49153).
The vulnerabilities were marked by the US Cybersecurity and Infrastructure Security Agency (CISA) as exploitable remotely with a low attack complexity.
The network management platform is deployed globally across critical manufacturing sectors, managing industrial switches and automation devices. Accordingly, industrial and critical manufacturing environments are at risk from the flaws; public damage remains to be reported.
Microsens recommended users to update to NMP Web+ Version 3.3.0 for Windows and Linux. CISA meanwhile suggested users minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
They are also advised to locate control system networks and remote devices behind firewalls and isolate them from business networks.
CISA also recommended use of Virtual Private Networks (VPNs) when remote access is required.
SDxCentral has contacted Microsens for further information.
Comments