CVE-2025-70517

Der Anforderungshandler der Firmware-Version 2.

Description

The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.

Metrics

8.8
Source: cna-v3
4.8 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-07 00:00 UTC

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-09 02:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
    • CWE: CWE-352
    • Reference: https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosure
    • SSVC: {"id":"CVE-2025-70517","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalIm…
  2. New CVE Received2026-10-07 15:16 UTC· cve@mitre.org
    • Description: The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/70xxx/CVE-2025-70517.json">CVE-2025-70517</a>
    • Reference: http://download.fanvil.com/Firmware/Release/X7A/
    • Reference: https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosure