PT-2026-107523 · Fanvil · X7A

CVE-2025-70516

·

Published

2026-10-07

·

Updated

2026-10-08

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Fanvil x7a version 2.6.0.1182
Description The websocket handler does not enforce proper authentication restrictions for sessionless users. This allows unauthorized individuals to access device resources, including operational logs, or execute diagnostic requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-70516

Affected Products

X7A