CVE-2025-63219

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
19/11/2025
Last modified:
12/01/2026

Description

The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compromise system integrity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:itel:iso-fm_firmware:2.0.0.0:*:*:*:*:*:*:*
cpe:2.3:h:itel:iso-fm:-:*:*:*:*:*:*:*