CVE-2025-64057

HIGH

Fanvil X210 Firmware - Path Traversal

Title source: rule
STIX 2.1

Description

Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and potentially modify the system configuration or other unspecified impacts.

Scores

CVSS v3 8.3
EPSS 0.0010
EPSS Percentile 28.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
fanvil/x210_firmware 2.12.20
Published Dec 05, 2025
Tracked Since Feb 18, 2026