CVE-2025-70515
Deferred Deferred - Pending Action

HTML Injection in Fanvil x7a Firmware Log Component

Vulnerability report for CVE-2025-70515, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: MITRE

Description

The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2025-70515 is a Cross-Site Scripting (XSS) vulnerability in Fanvil x7a firmware version 2.6.0.1182. The device log component fails to sanitize user-supplied data, allowing malicious HTML or JavaScript injection. This can execute arbitrary code in browsers viewing the log.

Detection Guidance

To detect this XSS vulnerability in Fanvil x7a firmware version 2.6.0.1182 or Fanvil PA2S SIP Gateway firmware version 2.12.44.9, inspect the device log component for unsanitized user input. Check if malicious scripts are being injected into logs by reviewing log entries for unexpected HTML or JavaScript code. Use browser developer tools to monitor network requests and responses for any reflected or stored XSS payloads in the log interface.

Impact Analysis

An attacker could inject malicious scripts into the device log, leading to privilege escalation or information disclosure. Users accessing the log may have their sessions compromised or sensitive data exposed.

Compliance Impact

This vulnerability could lead to unauthorized data access or disclosure, violating GDPR's data protection principles or HIPAA's security requirements for protected health information. Organizations using affected devices may face compliance violations.

Mitigation Strategies

Immediately update the affected Fanvil x7a firmware to the latest version available from Fanvil's official site. If an update is not available, restrict access to the device log component via network segmentation or firewall rules. Monitor logs for suspicious activity and disable the log feature if not required. Contact Fanvil support for patches or workarounds.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-70515. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart