Vulnerability Description
The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compromise system integrity.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Itel | Iso-Fm Firmware | 2.0.0.0 |
| Itel | Iso-Fm | - |
Related Weaknesses (CWE)
References
- https://github.com/shiky8/my--cve-vulnerability-research/tree/main/CVE-2025-6321ExploitThird Party Advisory
- https://www.itel.it/Product
FAQ
What is CVE-2025-63219?
CVE-2025-63219 is a vulnerability with a CVSS score of 7.5 (HIGH). The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active se...
How severe is CVE-2025-63219?
CVE-2025-63219 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-63219?
Check the references section above for vendor advisories and patch information. Affected products include: Itel Iso-Fm Firmware, Itel Iso-Fm.