7.5
CVE-2025-63219
- EPSS 0.15%
- Veröffentlicht 19.11.2025 15:15:50
- Zuletzt bearbeitet 12.01.2026 16:04:30
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compromise system integrity.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Itel ≫ Iso-fm Firmware Version2.0.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.358 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.