CVE-2025-64055 Details
Description
An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass.
An authentication bypass vulnerability has been identified in the Fanvil x210 V2 IP phone, specifically in firmware version 2.12.20. This vulnerability allows unauthenticated attackers on the local network to access administrative functions of the device, such as file uploads, firmware updates, and rebooting the device. The issue arises because the web application's authentication requirements can be bypassed, enabling unauthorized execution of CGI scripts that could modify the device's normal behavior.
Users are advised to update to firmware version 2.12.22.2, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64055.md | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64055.md | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| fanvil x210 firmware | 2.12.20 |
CPE
Remediation
| |
| fanvil x210 | 2.0 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 25, 2026 | CVE Translated | [email protected] |
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 9, 2026 | Modified Analysis | [email protected] |
| Dec 10, 2025 | Initial Analysis | [email protected] |
| Dec 5, 2025 | CVE Modified | CISA-ADP |
| Dec 3, 2025 | New CVE Received | [email protected] |