Executive brief
A security vulnerability exists in the Fanvil x210 enterprise IP phone, which is used for business communications. An attacker can trick a user into clicking a malicious link or submitting a specially crafted request, allowing the attacker to run unauthorized commands on the device. This could lead to a complete takeover of the phone, disruption of service, or unauthorized access to communication data.
Technical details
A reflected Cross-Site Scripting (XSS) vulnerability exists in the web management interface of Fanvil x210 V2 devices running firmware version 2.12.20. The vulnerability is located in the /cgi-bin/webconfig?page=upload&action=submit endpoint, where the 'filename' POST parameter is improperly neutralized before being reflected in the response. While standard <script> tags are blocked by CGI path separators, attackers can bypass this using event handlers (e.g., <img src=x onerror=...>) to execute arbitrary JavaScript in the context of the user's session. This can be leveraged to perform administrative actions, cause a denial of service, or potentially execute system commands. The issue is reportedly fixed in firmware version 2.12.22.2.
Affected products
- Fanvil x210 V2 2.12.20
Timeline
- 2025-03-01: other: Vulnerability discovered
- 2025-03-04: other: Initial contact with vendor
- 2025-04-28: patched: Firmware version 2.12.22.2 released
- 2025-12-05: advisory: CVE published