Login Bypass Vulnerability in NetAlertX Network Scanner by Jokob
CVE-2025-48952

9.4CRITICAL

Key Information:

Vendor

Jokob-sk

Status
Vendor
CVE Published:
4 July 2025

Badges

📈 Score: 388📰 News Worthy

What is CVE-2025-48952?

CVE-2025-48952 is a security vulnerability identified in the NetAlertX Network Scanner, a tool designed by Jokob-sk for scanning network presence and providing alert functionalities. This vulnerability centers around a flaw in the authentication logic of the application, which enables unauthorized access through a login bypass mechanism. Specifically, before version 25.6.7, the application improperly compares passwords using a loose equality operator in PHP, allowing attackers to exploit specially crafted "magic hash" values. These values can unintentionally evaluate to true due to the way loose comparisons handle numeric strings in PHP, particularly those formatted in scientific notation. This could pose significant risks to organizations using the software, as it opens the door for unauthorized users to gain access to network resources.

Potential impact of CVE-2025-48952

  1. Unauthorized Access: The primary concern surrounding CVE-2025-48952 is the risk of unauthorized access to sensitive network resources. Attackers could potentially compromise systems by bypassing authentication processes, leading to data breaches and exposure of confidential information.

  2. Operational Disruptions: With unauthorized users able to infiltrate network services, there is a heightened risk of operational disruptions. Attackers might manipulate or disable essential services, which can lead to significant downtime and a detrimental impact on business operations.

  3. Increased Threat Landscape: The existence of this vulnerability expands the threat landscape for organizations using NetAlertX, as it could serve as a gateway for further malicious activities. Unauthorized access could potentially lead to the installation of malware, data exfiltration, and the establishment of footholds for future attacks within the network.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

NetAlertX < 25.6.7

News Articles

CVE-2025-48952 | jokob-sk NetAlertX up to 25.6.6 front/index.php comparison (GHSA-4p4p-vq2v-9489 / EUVD-2025-20092)

A vulnerability, which was classified as critical, was found in jokob-sk NetAlertX up to 25.6.6. Affected is an unknown function of the file front/index.php. The manipulation leads to incorrect co…

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by Yanac.hu

  • Vulnerability published

  • Vulnerability Reserved

.