CVE 10 CRITICAL

CVE-2025-63224_CVE-2025-63224

10 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and networks are different. This allows full compromise of affected devices.

AI Analysis

Authentication Bypass vulnerability due to improper JWT validation, allowing attackers to reuse a valid JWT token and gain administrative access to affected devices.

Basic Information

ID CVE-2025-63224
Source mitre
Published Nov 19, 2025 at 00:00
Modified Nov 19, 2025 at 16:22

Affected Product

Vendor Itel
Product Itel DAB Encoder
Version IDEnc build 25aec8d
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 10 / 10
AI Severity Critical
Vendor Itel
Product Itel DAB Encoder
Version IDEnc build 25aec8d

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.