9.8
CVE-2025-64055
- EPSS 0.58%
- Veröffentlicht 03.12.2025 00:00:00
- Zuletzt bearbeitet 09.01.2026 02:18:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fanvil ≫ X210 Firmware Version2.12.20
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.58% | 0.682 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.