10
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Description
The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and networks are different. This allows full compromise of affected devices.
AI Analysis
Authentication Bypass vulnerability due to improper JWT validation, allowing attackers to reuse a valid JWT token and gain administrative access to affected devices.
Basic Information
ID
CVE-2025-63224
Source
mitre
Published
Nov 19, 2025 at 00:00
Modified
Nov 19, 2025 at 16:22
Affected Product
Vendor
Itel
Product
Itel DAB Encoder
Version
IDEnc build 25aec8d
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
10 / 10
AI Severity
Critical
Vendor
Itel
Product
Itel DAB Encoder
Version
IDEnc build 25aec8d