CVE-2025-64052: Command Injection
Published Dec 5, 2025
·Updated
An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arbitrary system commands.
Affected Software
3 affected components
Fanvil x210 V2
All of the following
Fanvil X210 Firmware=2.12.20
Fanvil x210=2.0
Event History
Dec 5, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64052?
CVE-2025-64052 is considered a critical vulnerability due to the potential for unauthenticated attackers to execute arbitrary system commands.
2
How do I fix CVE-2025-64052?
To fix CVE-2025-64052, update the Fanvil x210 V2 to the latest firmware version as provided by the manufacturer.
3
Who is affected by CVE-2025-64052?
Users of the Fanvil x210 V2 running firmware version 2.12.20 are affected by CVE-2025-64052.
4
Can CVE-2025-64052 be exploited remotely?
CVE-2025-64052 can only be exploited by unauthenticated attackers on the local network.
5
What should I do if I cannot update the firmware for CVE-2025-64052?
If updating the firmware is not possible, it is advisable to disconnect the device from the network until a patch is applied.