CVE-2025-63219

HIGH

ITEL ISO FM SFN Adapter - Session Hijacking

Title source: llm
STIX 2.1

Description

The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compromise system integrity.

Scores

CVSS v3 7.5
EPSS 0.0013
EPSS Percentile 31.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
itel/iso-fm_firmware 2.0.0.0
Published Nov 19, 2025
Tracked Since Feb 18, 2026