CVE-2025-63219: Itel Iso-Fm Firmware

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can access an active session without authentication, allowing them to control the device, modify configurations, and compromise system integrity.

Affected products

  • Itel Iso-Fm Firmware: version 2.0.0.0 only

Published 2025-11-19. Last modified 2026-06-17.