---
id: CVE-2025-64121
title: >-
  Authentication Bypass Using an Alternate Path or Channel vulnerability in
  Nuvation Energy Multi-Stack Controller (MSC) allows Authentication Bypass.This
  issue affects Multi-Stack Controller (MSC): from 2.3.8 before 2.5.1.
summary: >-
  Authentication Bypass Using an Alternate Path or Channel vulnerability in
  Nuvation Energy Multi-Stack Controller (MSC) allows Authentication Bypass.This
  issue affects Multi-Stack Controller (MSC): from 2.3.8 before 2.5.1.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-288
vendor: nuvationenergy
product: nplatform
affected:
  - 'nplatform >= 2.3.8, < 2.5.1'
patched:
  - nplatform 2.5.1
published: '2026-01-02'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64121'
references:
  - url: 'https://www.dragos.com/community/advisories/CVE-2025-64119'
    label: ot-cert@dragos.com
tags:
  - nvd
epss: 0.00397
epssPercentile: 0.31414
ingestedAt: '2026-09-30T23:29:32.523Z'
---

## Overview

Authentication Bypass Using an Alternate Path or Channel vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows Authentication Bypass.This issue affects Multi-Stack Controller (MSC): from 2.3.8 before 2.5.1.

## Affected

- `nplatform >= 2.3.8, < 2.5.1`

## Remediation

Upgrade past the affected range:

- `nplatform 2.5.1`
