CVE-2025-70521
Das Diagnosetool für Ping im Verwaltungsportal der Fanvil x7a-Firmware-Version 2.
criticalEPSS 0.4%
Description
The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.
Source: cvelistv5NVD (NIST)
Metrics
Show all metrics
Severity
critical
88.75
no public PoC known
9.8
Published
2026-10-07 00:00 UTC
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-07 21:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-77
- SSVC: {"id":"CVE-2025-70521","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-10-07 15:16 UTC· cve@mitre.org
- Description: The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2025/70xxx/CVE-2025-70521.json">CVE-2025-70521</a>
- Reference: http://download.fanvil.com/Firmware/Release/PA2S/
- Reference: https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosure