CVE-2025-70517
Der Anforderungshandler der Firmware-Version 2.
highEPSS 0.2%
Description
The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.
Source: cvelistv5NVD (NIST)
Metrics
Show all metrics
Severity
high
74.18
no public PoC known
8.8
Published
2026-10-07 00:00 UTC
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-09 02:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CVSS V3.1: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE: CWE-352
- Reference: https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosure
- SSVC: {"id":"CVE-2025-70517","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalIm…
- New CVE Received2026-10-07 15:16 UTC· cve@mitre.org
- Description: The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/70xxx/CVE-2025-70517.json">CVE-2025-70517</a>
- Reference: http://download.fanvil.com/Firmware/Release/X7A/
- Reference: https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosure