CVE-2025-49151: Microsens Nmp Web+

Critical severity, CVSS 9.3. EPSS: 0.6% chance of exploitation in the next 30 days.

The affected products could allow an unauthenticated attacker to generate forged JSON Web Tokens (JWT) to bypass authentication.

Affected products

  • Microsens Nmp Web+: up to and including 3.2.5

Published 2025-06-25. Last modified 2026-06-17.