CVE-2025-70521

Das Diagnosetool für Ping im Verwaltungsportal der Fanvil x7a-Firmware-Version 2.

criticalEPSS 0.4%

Description

The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.

Metrics

9.8
Source: cna-v3
34.9 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
critical
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-07 00:00 UTC

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-07 21:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • CWE: CWE-77
    • SSVC: {"id":"CVE-2025-70521","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  2. New CVE Received2026-10-07 15:16 UTC· cve@mitre.org
    • Description: The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/70xxx/CVE-2025-70521.json">CVE-2025-70521</a>
    • Reference: http://download.fanvil.com/Firmware/Release/PA2S/
    • Reference: https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosure