Login Bypass Vulnerability in NetAlertX Network Scanner by Jokob
CVE-2025-48952

9.4CRITICAL

Key Information:

Vendor

Jokob-sk

Status
Vendor
CVE Published:
4 July 2025

What is CVE-2025-48952?

NetAlertX, a network presence scanner and alerting framework, is susceptible to a login bypass vulnerability due to improper handling of authentication comparisons using loose equality in PHP. In versions before 25.6.7, the application uses the == operator, allowing specially crafted magic hash values to bypass password verification. This weak comparison can misinterpret specific password formats that result in true evaluations, leading to unauthorized access for users with particular 'weird' passwords. The issue has been resolved in version 25.6.7, reinforcing the need for users to update their installations promptly to safeguard against potential exploitation.

Affected Version(s)

NetAlertX < 25.6.7

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48952 : Login Bypass Vulnerability in NetAlertX Network Scanner by Jokob