Executive brief
A security vulnerability has been identified in Fanvil x210 enterprise IP phones, which are commonly used for business communications. An attacker can exploit this flaw to crash the device, causing a denial of service, or potentially gain unauthorized control over the phone. This could disrupt business operations and compromise the security of the communication endpoint.
Technical details
A classic buffer overflow (CWE-120) exists in the CGI script handling the '/cgi-bin/webconfig?page=upload&action=submit' endpoint on Fanvil x210 V2 devices running firmware 2.12.20. The vulnerability is triggered because the application fails to validate the length of the 'upload/dest' POST parameter. An attacker can provide a payload exceeding 704 characters to overflow the buffer, leading to a denial of service (DoS) or potential remote code execution (RCE). The issue is addressed in firmware version 2.12.22.2.
Affected products
- Fanvil x210 V2 2.12.20
Timeline
- 2025-03-01: disclosed: Vulnerability discovered by Spike Reply Cybersecurity Team
- 2025-03-04: other: Initial contact with vendor
- 2025-04-28: patched: Firmware version 2.12.22.2 released
- 2025-12-05: advisory: Public disclosure and CVE assignment