CVE-2025-70522
Deferred Deferred - Pending Action

Cross-Site Request Forgery in Fanvil x7a Firmware

Vulnerability report for CVE-2025-70522, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: MITRE

Description

The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Fanvil x7a firmware version 2.6.0.1182 has a vulnerability where the request handler does not enforce cross-origin resource protection for state-changing requests. This allows attackers to bypass cross-origin boundaries and perform Cross-Site Request Forgery (CSRF) attacks against any endpoint.

Impact Analysis

This vulnerability could allow an attacker to trick a user into performing unintended actions on the Fanvil x7a device, such as changing settings or executing commands, without their knowledge or consent.

Compliance Impact

This vulnerability enables Cross-Site Request Forgery (CSRF) attacks due to missing cross-origin protection in the Fanvil x7a firmware. Such attacks could allow unauthorized state-changing requests, potentially leading to unauthorized data access or modifications. This may impact compliance with GDPR (data protection) and HIPAA (healthcare data security) by increasing risks of unauthorized data breaches or integrity violations.

Mitigation Strategies

Update Fanvil x7a firmware to the latest version that includes cross-origin protection. Disable unnecessary web interfaces or restrict access to trusted networks. Implement network-level protections like firewalls to block unauthorized cross-origin requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-70522. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart