CVE WATCH / VULNERABILITY DETAIL

CVE-2025-70521

CRITICALCVSS 9.8NVD feed

Published 7 October 2026 · tracked since 8 October 2026

Description

The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2025-70521 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2025-70521

CRITICALCVSS 9.8NVD feed

Published 7 October 2026 · tracked since 8 October 2026

Description

The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]