PatchSiren

Fanvil CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Fanvil CVE published 2026-10-07

CVE-2025-70521

CVE-2025-70521 debrief based on CVE Program and NVD records. The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user-supplied input securely, allowing unauthenticated attackers to inject commands and run code in the underlying Android operating system. This vulnerability has significant implications for defenders responsible for managing and securing Fan [truncated]

Review Fanvil CVE published 2026-10-07

CVE-2025-70519

The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data, allowing for HTML injection and potential JavaScript code execution. This vulnerability impacts the device's security, potentially enabling attackers to execute malicious code on browsers rendering the device log component. Defenders should assess exposure and prioritize ve [truncated]

Review Fanvil CVE published 2026-10-07

CVE-2025-70516

CVE-2025-70516 debrief: Fanvil x7a firmware version 2.6.0.1182 websocket handler lacks authentication restrictions, allowing unauthorized access to device resources such as operational logs or diagnostic requests. This vulnerability impacts organizations using the affected firmware, potentially exposing them to unauthorized device access and data breaches. Defenders should assess exposure and implement co [truncated]