CVE-2025-64053
BaseFortify
Publication date: 2025-12-05
Last updated on: 2025-12-10
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tenda | x210_firmware | 2.12.20 |
| tenda | x210 | 2.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-120 | The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a buffer overflow in Fanvil x210 devices running version 2.12.20. It occurs when an attacker sends a specially crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint, which can cause the device to crash (denial of service) or potentially allow the attacker to execute arbitrary commands on the device.
How can this vulnerability impact me? :
The vulnerability can impact you by causing your Fanvil x210 device to become unavailable due to a denial of service attack. Additionally, it may allow an attacker to execute arbitrary commands on the device, which could lead to unauthorized control, data compromise, or further attacks within your network.