Junglewise Threat Intelligence

CVE-2025-64052: Fanvil x210 V2 command injection in web configuration interface

CVE-2025-64052 · Severity: medium · CVSS 5.1 · Published 2025-12-05

Technologies: Fanvil X210 V2, Fanvil X210 Firmware, Fanvil X210. Vendors: Fanvil.

Executive brief

Fanvil x210 V2 is an enterprise-grade IP phone used for business communications. A security flaw in its web-based configuration interface allows an attacker on the same local network to take control of the device by executing unauthorized system commands. This could lead to eavesdropping, service disruption, or using the phone as a foothold to attack other parts of the corporate network.

Technical details

Multiple command injection vulnerabilities exist in the web configuration interface of Fanvil x210 V2 (firmware 2.12.20). The flaws are located within the file upload functionality at /cgi-bin/webconfig, specifically affecting the 'upload/dest' and 'upload/newfile' parameters. An unauthenticated attacker on the local network can exploit these by sending a specially crafted multipart POST request containing shell metacharacters. The vulnerability stems from improper neutralization of special elements used in a command (CWE-77). Successful exploitation allows for arbitrary code execution with the privileges of the web server. The issue is reportedly addressed in firmware version 2.12.22.2.

Affected products

  • Fanvil x210 V2 2.12.20

Timeline

  • 2025-03-01: disclosed: Vulnerability discovered by Spike Reply Cybersecurity Team
  • 2025-03-04: other: Initial contact with vendor
  • 2025-04-28: patched: Vendor released firmware v2.12.22.2 which addresses the issue
  • 2025-12-05: advisory: Public disclosure and CVE assignment

References

Related threats