Executive brief
The Fanvil x210 V2 is a high-end enterprise IP phone used for business communications. A security flaw in its web-based configuration tool allows an unauthorized person on the same local network to upload and store files on the device's internal memory. This could allow an attacker to disrupt the phone's operation or modify its settings, potentially impacting business communications and device reliability.
Technical details
An arbitrary file write vulnerability exists in the web configuration interface of Fanvil x210 V2 firmware version 2.12.20. The vulnerability stems from a lack of input validation and sanitization in the 'upload/dest' parameter of the webconfig CGI script, which handles font and translation file uploads. Because the web service (httpd) runs with root privileges, an unauthenticated attacker on the local network (adjacent) can use path traversal or direct path injection to write files to any location on the filesystem. This can be used to overwrite critical system files or configuration data. The issue is addressed in firmware version 2.12.22.2.
Affected products
- Fanvil x210 V2 2.12.20
Timeline
- 2025-03-01: other: Vulnerability discovered
- 2025-03-04: other: Initial contact with vendor
- 2025-04-28: patched: Firmware v2.12.22.2 released
- 2025-12-05: disclosed: Public disclosure and CVE assignment