The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory (ICSA-25-175-07) regarding three severe vulnerabilities in MICROSENS NMP Web+ network management software.
These flaws, discovered by Claroty Team82 researchers and coordinated with Germany’s BSI CERT-Bund, enable unauthenticated attackers to bypass authentication, maintain persistent access, and execute arbitrary code on affected systems.
The vulnerabilities impact NMP Web+ versions 3.2.5 and earlier on both Windows and Linux platforms, posing significant risks to critical infrastructure sectors globally.
Three critical CVEs compromise the platform’s security:
Researchers warn that these vulnerabilities can be chained: attackers first exploit CVE-2025-49151 to gain valid tokens, then leverage CVE-2025-49153 for remote code execution, achieving “zero to hero” system control.
Industrial systems using NMP Web+ for network device management are particularly vulnerable, especially those exposed to the internet.
MICROSENS has released NMP Web+ Version 3.3.0 for Windows and Linux to address all vulnerabilities.
CISA mandates immediate installation of this update and recommends additional defensive measures:
Organizations should monitor access logs for suspicious activity and apply cybersecurity best practices outlined in CISA’s Defense-in-Depth Strategies.
As of July 1, 2025, no active exploits have been reported, but exposed systems remain high-risk targets.
These vulnerabilities affect critical manufacturing sectors worldwide, with MICROSENS headquarters based in Germany.
The flaws highlight systemic risks in industrial control systems (ICS), where unpatched network management tools can serve as entry points for sophisticated attacks.
Security researchers emphasize that while patching is urgent, long-term security requires continuous vulnerability assessments and adherence to frameworks like CISA’s ICS-TIP-12-146-01B intrusion detection guidelines.
Organizations using MICROSENS devices must prioritize this update to prevent potential operational disruption and system compromise.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates
The post MICROSENS NMP Web+ Bugs Allow Unauthenticated Code Execution appeared first on Cyber Security News.
A new weekend has arrived, and today, you can save big on the 4K Movies,…
Resident Evil Requiem fans believe next month’s mysterious content update will add a new version…
Wrestlemania 42 is finally here, and I’m here in Las Vegas at Allegiant Stadium to…
Game of Thrones alum Charles Dance has reportedly entered talks to join The Batman Part…
Tension: We crave sustainable food innovation yet recoil from eating anything that didn’t come from…
Tension: We perform intimacy online while starving for genuine connection offline. Noise: The algorithm rewards…
This website uses cookies.