Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 12 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Itel iso-fm
Itel iso-fm Firmware |
|
| CPEs | cpe:2.3:h:itel:iso-fm:-:*:*:*:*:*:*:* cpe:2.3:o:itel:iso-fm_firmware:2.0.0.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Itel iso-fm
Itel iso-fm Firmware |
Fri, 21 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Itel
Itel iso Fm Sfn Adapter |
|
| Vendors & Products |
Itel
Itel iso Fm Sfn Adapter |
Wed, 19 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Wed, 19 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compromise system integrity. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-19T21:36:02.845Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63219
Updated: 2025-11-19T15:47:56.148Z
Status : Analyzed
Published: 2025-11-19T15:15:50.600
Modified: 2026-01-12T16:04:30.650
Link: CVE-2025-63219
No data.
OpenCVE Enrichment
Updated: 2025-11-21T09:16:23Z