MICROSENS NMP Web+ Path Traversal Vulnerability Allowing Arbitrary File Overwrite and Code Execution

Vulnerability

A path traversal vulnerability has been identified in MICROSENS NMP Web+ versions through 3.2.5. This vulnerability allows an unauthenticated attacker to overwrite files and execute arbitrary code on the affected system.

Impact

Exploitation of this vulnerability could lead to unauthorized file overwriting and execution of arbitrary code on the system.

Remediation

Users are advised to update to NMP Web+ Version 3.3.0 for Windows and Linux. For additional guidance, CISA recommends minimizing network exposure for control system devices, using firewalls to isolate control system networks from business networks, and employing secure remote access methods such as Virtual Private Networks (VPNs).

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
7.7
relevance
0.2
threat
0.1
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.