Login Bypass Vulnerability in NetAlertX Network Scanner by Jokob
CVE-2025-48952
9.4CRITICAL
What is CVE-2025-48952?
NetAlertX, a network presence scanner and alerting framework, is susceptible to a login bypass vulnerability due to improper handling of authentication comparisons using loose equality in PHP. In versions before 25.6.7, the application uses the ==
operator, allowing specially crafted magic hash values to bypass password verification. This weak comparison can misinterpret specific password formats that result in true evaluations, leading to unauthorized access for users with particular 'weird' passwords. The issue has been resolved in version 25.6.7, reinforcing the need for users to update their installations promptly to safeguard against potential exploitation.
Affected Version(s)
NetAlertX < 25.6.7