Junglewise Threat Intelligence

CVE-2025-64055: Fanvil x210 V2 authentication bypass in httpd cgi-bin

CVE-2025-64055 · Severity: critical · CVSS 9.8 · Published 2025-12-03

Technologies: Fanvil X210 V2, Fanvil X210 Firmware, Fanvil X210. Vendors: Fanvil.

Executive brief

A security vulnerability has been identified in Fanvil x210 V2 enterprise IP phones, which are used for business communications. An attacker on the same network can bypass security controls to access the device's administrative interface without a password. This allows unauthorized individuals to reboot the phone, upload malicious files, or modify system settings, potentially leading to eavesdropping or service disruption.

Technical details

An authentication bypass vulnerability exists in the httpd server configuration of Fanvil x210 V2 firmware version 2.12.20. The web server configuration only enforces authentication for the /html path, leaving other paths such as /cgi-bin unprotected. An unauthenticated attacker on the local network can exploit this by directly calling CGI scripts to perform administrative actions like file uploads, firmware updates, and device reboots. The issue is addressed in firmware version 2.12.22.2.

Affected products

  • Fanvil x210 V2 2.12.20

Timeline

  • 2025-01-03: disclosed: Vulnerability discovered by Spike Reply Cybersecurity Team
  • 2025-03-04: other: Initial contact with vendor
  • 2025-04-28: patched: Firmware version 2.12.22.2 released
  • 2025-12-03: advisory: CVE published

References

Related threats