CVE-2025-64057

HIGH

Fanvil x210 V2 2.12.20 - Unauthenticated Path Traversal and Arbitrary File Write

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and potentially modify the system configuration or other unspecified impacts.

Scores

CVSS v3 8.3
EPSS 0.0080
EPSS Percentile 51.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
fanvil/x210_firmware 2.12.20
Published Dec 05, 2025
Tracked Since Feb 18, 2026