Login Bypass Vulnerability in NetAlertX Network Scanner by Jokob
CVE-2025-48952
Key Information:
Badges
What is CVE-2025-48952?
CVE-2025-48952 is a security vulnerability identified in the NetAlertX Network Scanner, a tool designed by Jokob-sk for scanning network presence and providing alert functionalities. This vulnerability centers around a flaw in the authentication logic of the application, which enables unauthorized access through a login bypass mechanism. Specifically, before version 25.6.7, the application improperly compares passwords using a loose equality operator in PHP, allowing attackers to exploit specially crafted "magic hash" values. These values can unintentionally evaluate to true due to the way loose comparisons handle numeric strings in PHP, particularly those formatted in scientific notation. This could pose significant risks to organizations using the software, as it opens the door for unauthorized users to gain access to network resources.
Potential impact of CVE-2025-48952
-
Unauthorized Access: The primary concern surrounding CVE-2025-48952 is the risk of unauthorized access to sensitive network resources. Attackers could potentially compromise systems by bypassing authentication processes, leading to data breaches and exposure of confidential information.
-
Operational Disruptions: With unauthorized users able to infiltrate network services, there is a heightened risk of operational disruptions. Attackers might manipulate or disable essential services, which can lead to significant downtime and a detrimental impact on business operations.
-
Increased Threat Landscape: The existence of this vulnerability expands the threat landscape for organizations using NetAlertX, as it could serve as a gateway for further malicious activities. Unauthorized access could potentially lead to the installation of malware, data exfiltration, and the establishment of footholds for future attacks within the network.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
NetAlertX < 25.6.7
News Articles
CVE-2025-48952 | jokob-sk NetAlertX up to 25.6.6 front/index.php comparison (GHSA-4p4p-vq2v-9489 / EUVD-2025-20092)
A vulnerability, which was classified as critical, was found in jokob-sk NetAlertX up to 25.6.6. Affected is an unknown function of the file front/index.php. The manipulation leads to incorrect co…
References
CVSS V3.1
Timeline
- 📰
First article discovered by Yanac.hu
Vulnerability published
Vulnerability Reserved
