Executive brief
Fanvil x210 V2 is an enterprise-grade IP phone used for business communications. A security flaw in its web-based configuration interface allows an attacker on the same local network to take control of the device by executing unauthorized system commands. This could lead to eavesdropping, service disruption, or using the phone as a foothold to attack other parts of the corporate network.
Technical details
Multiple command injection vulnerabilities exist in the web configuration interface of Fanvil x210 V2 (firmware 2.12.20). The flaws are located within the file upload functionality at /cgi-bin/webconfig, specifically affecting the 'upload/dest' and 'upload/newfile' parameters. An unauthenticated attacker on the local network can exploit these by sending a specially crafted multipart POST request containing shell metacharacters. The vulnerability stems from improper neutralization of special elements used in a command (CWE-77). Successful exploitation allows for arbitrary code execution with the privileges of the web server. The issue is reportedly addressed in firmware version 2.12.22.2.
Affected products
- Fanvil x210 V2 2.12.20
Timeline
- 2025-03-01: disclosed: Vulnerability discovered by Spike Reply Cybersecurity Team
- 2025-03-04: other: Initial contact with vendor
- 2025-04-28: patched: Vendor released firmware v2.12.22.2 which addresses the issue
- 2025-12-05: advisory: Public disclosure and CVE assignment