CVE-2025-64054
BaseFortify
Publication date: 2025-12-05
Last updated on: 2025-12-11
Assigner: MITRE
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| tenda | x210_firmware | 2.12.20 |
| tenda | x210 | 2.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a reflected Cross Site Scripting (XSS) issue in Fanvil x210 2.12.20 devices. It allows attackers to send a specially crafted POST request to the /cgi-bin/webconfig?page=upload&action=submit endpoint, which can cause a denial of service or potentially allow the attacker to execute arbitrary commands on the device.
How can this vulnerability impact me? :
The vulnerability can impact you by causing a denial of service on the affected Fanvil x210 device, disrupting its normal operation. Additionally, it may allow attackers to execute arbitrary commands, potentially compromising the device's security and control.