A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Dec 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fanvil
Fanvil x210 V2 |
|
| Vendors & Products |
Fanvil
Fanvil x210 V2 |
Fri, 05 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 05 Dec 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-12-05T00:00:00.000Z
Updated: 2025-12-05T19:23:34.794Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-64054
Updated: 2025-12-05T19:23:25.577Z
Status : Received
Published: 2025-12-05T16:15:50.330
Modified: 2025-12-05T20:15:57.357
Link: CVE-2025-64054
No data.