Search
Search Results (14 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-70515 | 1 Fanvil | 1 X7a | 2026-10-09 | N/A |
| The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component. | ||||
| CVE-2025-70516 | 1 Fanvil | 1 X7a | 2026-10-09 | 9.1 Critical |
| The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests. | ||||
| CVE-2025-70517 | 1 Fanvil | 1 X7a | 2026-10-09 | 8.8 High |
| The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint. | ||||
| CVE-2025-70518 | 1 Fanvil | 1 X7a | 2026-10-09 | 10 Critical |
| The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system. | ||||
| CVE-2025-70519 | 1 Fanvil | 1 X7a | 2026-10-09 | 6.1 Medium |
| The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component. | ||||
| CVE-2025-70520 | 1 Fanvil | 1 X7a | 2026-10-09 | N/A |
| The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests. | ||||
| CVE-2025-70521 | 1 Fanvil | 1 X7a | 2026-10-09 | 9.8 Critical |
| The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system. | ||||
| CVE-2025-70522 | 1 Fanvil | 1 X7a | 2026-10-09 | 8.8 High |
| The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint. | ||||
| CVE-2025-64055 | 1 Fanvil | 3 X210, X210 Firmware, X210 V2 | 2026-01-09 | 9.8 Critical |
| An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass. | ||||
| CVE-2025-64056 | 1 Fanvil | 3 X210, X210 Firmware, X210 V2 | 2026-01-09 | 4.3 Medium |
| File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem. | ||||
| CVE-2025-64057 | 1 Fanvil | 3 X210, X210 Firmware, X210 V2 | 2026-01-09 | 8.3 High |
| Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and potentially modify the system configuration or other unspecified impacts. | ||||
| CVE-2025-64053 | 1 Fanvil | 3 X210, X210 Firmware, X210 V2 | 2026-01-09 | 7.5 High |
| A Buffer overflow vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint. | ||||
| CVE-2025-64054 | 1 Fanvil | 3 X210, X210 Firmware, X210 V2 | 2026-01-09 | 9.6 Critical |
| A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint. | ||||
| CVE-2025-64052 | 1 Fanvil | 3 X210, X210 Firmware, X210 V2 | 2025-12-31 | 5.1 Medium |
| An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arbitrary system commands. | ||||
Page 1 of 1.