Junglewise Threat Intelligence

CVE-2025-64057: Fanvil x210 V2 directory traversal and RCE in web interface

CVE-2025-64057 · Severity: high · CVSS 8.3 · Published 2025-12-05

Technologies: Fanvil X210 V2, Fanvil X210 Firmware, Fanvil X210. Vendors: Fanvil.

Executive brief

A security vulnerability in Fanvil x210 V2 enterprise IP phones allows unauthorized individuals on the same local network to take full control of the device. By exploiting a flaw in how the phone handles file uploads, an attacker can modify system settings or execute malicious commands. This could lead to eavesdropping on calls, service disruption, or using the phone as a foothold to attack other parts of the corporate network.

Technical details

A directory traversal vulnerability exists in the web configuration interface of Fanvil x210 V2 devices running firmware version 2.12.20. The flaw resides in the file upload functionality, which fails to validate file extensions and improperly handles destination paths. An unauthenticated attacker on the adjacent network can upload a malicious shell script, which the system automatically grants execution permissions to before moving it to a user-specified directory. By placing the script in the /webroot/cgi-bin directory, the attacker can trigger its execution via the CGI processor, resulting in full remote command execution (RCE) with system privileges. The issue is reportedly addressed in firmware version 2.12.22.2.

Affected products

  • Fanvil x210 V2 2.12.20

Timeline

  • 2025-03-01: disclosed: Vulnerability discovered by Spike Reply Cybersecurity Team
  • 2025-03-04: other: Initial contact with vendor
  • 2025-04-28: patched: Firmware version 2.12.22.2 released
  • 2025-12-05: advisory: NVD publication date

References

Related threats