The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and networks are different. This allows full compromise of affected devices.
Metrics
Affected Vendors & Products
References
History
Thu, 15 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Itel id Mux
Itel id Mux Firmware |
|
| CPEs | cpe:2.3:h:itel:id_mux:-:*:*:*:*:*:*:* cpe:2.3:o:itel:id_mux_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Itel id Mux
Itel id Mux Firmware |
Mon, 01 Dec 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Itel
Itel dab Mux |
|
| Vendors & Products |
Itel
Itel dab Mux |
Wed, 19 Nov 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-288 | |
| Metrics |
cvssV3_1
|
Tue, 18 Nov 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same firmware, even if the passwords and networks are different. This allows full compromise of affected devices. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-18T00:00:00.000Z
Updated: 2025-11-19T14:32:15.920Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63217
Updated: 2025-11-19T14:32:11.444Z
Status : Analyzed
Published: 2025-11-18T22:15:51.750
Modified: 2026-01-15T21:57:14.860
Link: CVE-2025-63217
No data.
ReportizFlow