CVE-2025-63219
7.5ITEL · ISO FM SFN Adapter
The ITEL ISO FM SFN Adapter is susceptible to session hijacking via the /home.html endpoint, allowing unauthenticated attackers to hijack active sessions and compromise device integrity.
Executive summary
The ITEL ISO FM SFN Adapter is vulnerable to unauthenticated session hijacking, which poses a significant risk of total device compromise.
Vulnerability
This vulnerability involves improper session management on the /home.html endpoint, which permits an unauthenticated attacker to hijack active sessions and gain unauthorized administrative control over the adapter.
Business impact
Successful exploitation grants an attacker the ability to modify device configurations and compromise system integrity. Given the CVSS score of 7.5, this high-severity vulnerability represents a significant risk to operational continuity and network security, as attackers could potentially use the adapter as a pivot point within the infrastructure.
Remediation
Immediate Action: Since no specific patch is currently identified, restrict network access to the device interface to trusted management subnets only and disable the web interface if it is not strictly required for operations.
Proactive Monitoring: Monitor network access logs for unauthorized connections to the /home.html endpoint and review device configuration change logs for suspicious activity.
Compensating Controls: Deploy a Web Application Firewall (WAF) or local firewall rules to block access to the management interface from untrusted networks and enforce strict session timeout policies.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the researcher write-up referenced in the CVE record.
Analyst recommendation
Due to the lack of an official patch and the availability of a public proof-of-concept, users must treat this vulnerability with high urgency. Administrators should immediately isolate the affected device from the public internet and restrict management access to authorized internal personnel to prevent potential session hijacking and subsequent system compromise.