CVE-2025-70516: Critical severity Fanvil x7a firmware vulnerability
Published Oct 7, 2026
·Updated
The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.
Affected Software
1 affected component
Fanvil x7a firmware=2.6.0.1182
Event History
Oct 7, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness