# ICS JWT auth bypass via hard-coded constants

Source: https://startwithidentity.com/cves/cve-2025-49151/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

## What broke

An industrial product covered by CISA ICSA-25-175-07 verified [JWTs](https://startwithidentity.com/glossary/jwt/) against hard-coded constants (CWE-547) rather than a real key. Anyone who read the firmware or the advisory can mint a valid token. Critical. Vendor patched.

## Why it matters

OT and ICS identity is often "we added JWT in the last firmware." Hard-coded secrets are how that upgrade fails. The same lesson as [hard-coded credentials](https://startwithidentity.com/glossary/jwt/) in enterprise SaaS, with a plant-floor blast radius.

## What to do

- Apply the firmware named in ICSA-25-175-07.
- Rotate any identity secret that shipped in the image. A patch that leaves the old constant in place is not a fix.
- For any ICS or appliance SSO, ask the vendor where the JWT signing key lives. If the answer is "in the firmware," do not federate it to your corporate IdP.

## After you patch

Token-layer flaws produce credentials that keep working after the patch, so remediation is about invalidating what was issued.

- **Rotate the signing keys** published at your [JWKS](https://startwithidentity.com/glossary/jwks/) endpoint, then confirm relying parties refetch on an unknown key id rather than caching indefinitely.
- **Revoke [refresh tokens](https://startwithidentity.com/glossary/refresh-token/) and sessions.** Access tokens expire on their own; refresh tokens are the ones that turn a short compromise into months of access.
- **Audit client registrations and consent grants** created during the window, particularly any client with broad scopes or a redirect URI you do not recognize.
- **Verify validation on your side**: pinned algorithms, issuer and audience checks, and no acceptance of `alg: none`. See [JWT](https://startwithidentity.com/glossary/jwt/) and the [validate a JWT recipe](https://startwithidentity.com/recipes/validate-a-jwt/).

## Sources

- [NVD: CVE-2025-49151](https://nvd.nist.gov/vuln/detail/CVE-2025-49151)
- CISA ICSA-25-175-07
