Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Critical Microsens Product Flaws Allow Hackers to Go ‘From Zero to Hero’

Posted on July 1, 2025July 1, 2025 By CWS

Vital vulnerabilities affecting a product made by Germany-based Microsens might be exploited by hackers to conduct distant assaults in opposition to organizations.

Microsens gives a variety of connectivity and automation options for industrial organizations and enterprises, together with switches, converters, constructing controllers, and transceivers. The corporate’s NMP Internet+ product allows customers to manage, monitor and configure industrial switches and different Microsens community tools.

An advisory revealed by the cybersecurity company CISA final week knowledgeable organizations that the Microsens NMP Internet+ product is affected by two vital and one high-severity vulnerability.

The vital vulnerabilities might be exploited by an unauthenticated attacker to generate solid JSON Internet Tokens and bypass authentication (CVE-2025-49151) and overwrite information and execute arbitrary code (CVE-2025-49153). The high-severity situation is expounded to the truth that the JSON Internet Tokens don’t expire.

Noam Moshe, vulnerability researcher at Claroty’s Team82, who has been credited for the invention, advised SecurityWeek that an attacker may chain these flaws.

One vulnerability can be utilized to acquire a legitimate authentication token that gives entry to the focused system, whereas the second bug allows the attacker to overwrite vital information on the server, giving them full management over the system on the OS degree.

“These two vulnerabilities collectively enable an attacker to leap ‘from zero to hero’, which means gaining full management over the system with no need to have any prior information/credentials to the server,” Moshe defined.

The researcher identified that an attacker wants entry to the net server related to the focused Microsens NMP Internet+ occasion to take advantage of the vulnerabilities, however warned that a number of situations are uncovered to the web and probably weak to assaults.Commercial. Scroll to proceed studying.

CISA mentioned it’s not conscious of assaults exploiting these vulnerabilities and the seller has launched updates to patch the issues (model 3.3.0 for Home windows and Linux). 

In accordance with the company’s advisory, the impacted product is used worldwide, together with within the vital manufacturing sector.

Associated: Iranian Hackers’ Most well-liked ICS Targets Left Open Amid Recent US Assault Warning

Associated: Siemens Notifies Prospects of Microsoft Defender Antivirus Challenge

Associated: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, CISA

Security Week News Tags:Critical, Flaws, Hackers, Hero, Microsens, Product

Post navigation

Previous Post: LevelBlue to Acquire Trustwave to Create Major MSSP
Next Post: Europol Dismantles Fraud Crypto Investment Ring That Tricked 5000+ Victims Worldwide

Related Posts

Cerby Raises $40 Million for Identity Automation Platform Security Week News
FreeType Zero-Day Found by Meta Exploited in Paragon Spyware Attacks Security Week News
Chrome 137 Update Patches High-Severity Vulnerabilities Security Week News
Chinese Hacking Group ‘Earth Lamia’ Targets Multiple Industries Security Week News
1,000 Instantel Industrial Monitoring Devices Possibly Exposed to Hacking Security Week News
NATO-Flagged Vulnerability Tops Latest VMware Security Patch Batch Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Massive Android Ad Fraud ‘IconAds’ Leverages Google Play to Attack Phone Users
  • Your AI Agents Might Be Leaking Data — Watch this Webinar to Learn How to Stop It
  • Google Ordered to Pay $314M for Misusing Android Users’ Cellular Data Without Permission
  • New Hpingbot Abusing Pastebin for Payload Delivery and Hping3 Tool to Launch DDoS Attacks
  • Azure API Vulnerabilities Leak VPN Keys and Built-In Roles Allow Over-Privileged Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Massive Android Ad Fraud ‘IconAds’ Leverages Google Play to Attack Phone Users
  • Your AI Agents Might Be Leaking Data — Watch this Webinar to Learn How to Stop It
  • Google Ordered to Pay $314M for Misusing Android Users’ Cellular Data Without Permission
  • New Hpingbot Abusing Pastebin for Payload Delivery and Hping3 Tool to Launch DDoS Attacks
  • Azure API Vulnerabilities Leak VPN Keys and Built-In Roles Allow Over-Privileged Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News