Junglewise Threat Intelligence

CVE-2025-64054: Fanvil x210 reflected XSS in upload page

CVE-2025-64054 · Severity: critical · CVSS 9.6 · Published 2025-12-05

Technologies: Fanvil X210 V2, Fanvil X210 Firmware, Fanvil X210. Vendors: Fanvil.

Executive brief

A security vulnerability exists in the Fanvil x210 enterprise IP phone, which is used for business communications. An attacker can trick a user into clicking a malicious link or submitting a specially crafted request, allowing the attacker to run unauthorized commands on the device. This could lead to a complete takeover of the phone, disruption of service, or unauthorized access to communication data.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in the web management interface of Fanvil x210 V2 devices running firmware version 2.12.20. The vulnerability is located in the /cgi-bin/webconfig?page=upload&action=submit endpoint, where the 'filename' POST parameter is improperly neutralized before being reflected in the response. While standard <script> tags are blocked by CGI path separators, attackers can bypass this using event handlers (e.g., <img src=x onerror=...>) to execute arbitrary JavaScript in the context of the user's session. This can be leveraged to perform administrative actions, cause a denial of service, or potentially execute system commands. The issue is reportedly fixed in firmware version 2.12.22.2.

Affected products

  • Fanvil x210 V2 2.12.20

Timeline

  • 2025-03-01: other: Vulnerability discovered
  • 2025-03-04: other: Initial contact with vendor
  • 2025-04-28: patched: Firmware version 2.12.22.2 released
  • 2025-12-05: advisory: CVE published

References

Related threats