9.8
CVE-2025-64055
- EPSS 0.52%
- Veröffentlicht 03.12.2025 00:00:00
- Zuletzt bearbeitet 25.09.2026 23:10:00
- Erkennungen
An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fanvil ≫ X210 Firmware Version 2.12.20
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.52% | 0.415 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64055.md