CVE-2025-28231

CRITICAL

Itel Electronics IP Stream <1.7.0.6 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Incorrect access control in Itel Electronics IP Stream v1.7.0.6 allows unauthorized attackers to execute arbitrary commands with Administrator privileges.

Scores

CVSS v3 9.1
EPSS 0.0033
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Published Apr 18, 2025
Tracked Since Feb 18, 2026