CVE-2025-64054: XSS
A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64054?
CVE-2025-64054 is a high severity reflected Cross Site Scripting (XSS) vulnerability.
How do I fix CVE-2025-64054?
To fix CVE-2025-64054, ensure that the firmware of the Fanvil x210 devices is updated to the latest version provided by the vendor.
What devices are affected by CVE-2025-64054?
CVE-2025-64054 affects Fanvil x210 devices running firmware version 2.12.20.
What are the potential impacts of CVE-2025-64054?
Exploitation of CVE-2025-64054 can lead to denial of service or execution of arbitrary commands on the affected devices.
Is there a workaround for CVE-2025-64054?
Currently, the recommended approach is to apply firmware updates as there are no known effective workarounds for CVE-2025-64054.