Itel's vulnerability profile centers on a narrow range of identity and access management appliances, including its ID Mux, ID Gateway, and ID Encoder products and their associated firmware. The durable signal is a recurring pattern of authentication and access-control weaknesses—including improper authentication mechanisms, session fixation, authentication bypass paths, and access-control flaws—that are characteristic of identity-handling infrastructure. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Itel over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-63224CRITICAL The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from | Nov 19, 2025 | 10.0 | 31 | NO | NO |
CVE-2025-63216CRITICAL The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained fro | Nov 18, 2025 | 10.0 | 31 | NO | NO |
CVE-2025-63217CRITICAL The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from on | Nov 18, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-63219HIGH The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper session management on the /home.html endpoint. An attacker can | Nov 19, 2025 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Itel.
Media articles that mention a CVE ID that affects a product developed by Itel — matched by CVE ID, not by vendor name.