VYPR

X210 Firmware

by Fanvil

CVEs (6)

  • CVE-2025-64055CriDec 3, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass.

  • CVE-2025-64054CriDec 5, 2025
    risk 0.62cvss 9.6epss 0.00

    A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint.

  • CVE-2025-64057HigDec 5, 2025
    risk 0.54cvss 8.3epss 0.01

    Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and potentially modify the system configuration or other unspecified impacts.

  • CVE-2025-64053HigDec 5, 2025
    risk 0.49cvss 7.5epss 0.03

    A Buffer overflow vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint.

  • CVE-2025-64052MedDec 5, 2025
    risk 0.33cvss 5.1epss 0.03

    An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arbitrary system commands.

  • CVE-2025-64056MedDec 5, 2025
    risk 0.28cvss 4.3epss 0.00

    File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem.