Junglewise Threat Intelligence

CVE-2025-64053: Fanvil x210 buffer overflow in webconfig upload

CVE-2025-64053 · Severity: high · CVSS 7.5 · Published 2025-12-05

Technologies: Fanvil X210 V2, Fanvil X210 Firmware, Fanvil X210. Vendors: Fanvil.

Executive brief

A security vulnerability has been identified in Fanvil x210 enterprise IP phones, which are commonly used for business communications. An attacker can exploit this flaw to crash the device, causing a denial of service, or potentially gain unauthorized control over the phone. This could disrupt business operations and compromise the security of the communication endpoint.

Technical details

A classic buffer overflow (CWE-120) exists in the CGI script handling the '/cgi-bin/webconfig?page=upload&action=submit' endpoint on Fanvil x210 V2 devices running firmware 2.12.20. The vulnerability is triggered because the application fails to validate the length of the 'upload/dest' POST parameter. An attacker can provide a payload exceeding 704 characters to overflow the buffer, leading to a denial of service (DoS) or potential remote code execution (RCE). The issue is addressed in firmware version 2.12.22.2.

Affected products

  • Fanvil x210 V2 2.12.20

Timeline

  • 2025-03-01: disclosed: Vulnerability discovered by Spike Reply Cybersecurity Team
  • 2025-03-04: other: Initial contact with vendor
  • 2025-04-28: patched: Firmware version 2.12.22.2 released
  • 2025-12-05: advisory: Public disclosure and CVE assignment

References

Related threats