Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-70515

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Fanvil x7a 设备固件版本 2.6.0.1182 的日志组件未正确对反射性用户输入数据进行清理或编码。由于缺乏必要的清理机制,攻击者可以注入 HTML 代码,从而在渲染该设备日志组件的任何目标浏览器中执行恶意 JavaScript 代码。

AI Predicted 6.1 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1189 · Drive-by Compromise
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-70515

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2025-70515

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-70515

请登录查看更多情报信息。

Other References for CVE-2025-70515 (3)

Same Patch Batch · n/a · 2026-10-07 · 16 CVEs total

CVE-2026-88514 iTerm2 macOS 低于 3.6.12 本地敏感信息泄露漏洞
CVE-2026-42618 NTFS-3G堆缓冲区溢出漏洞
CVE-2026-46572 ntfs-3G堆缓冲区溢出漏洞
CVE-2026-42616 NTFS-3G heap缓冲区溢出漏洞
CVE-2026-42617 ntfs-3g堆缓冲区溢出漏洞
CVE-2026-46569 ntfs-3G低于2026.7.7的堆缓冲区溢出漏洞
CVE-2026-46571 NTFS-3G 越界读漏洞,影响 2026.7.7 前版本
CVE-2026-46570 NTFS-3G <2026.7.7堆溢出漏洞
CVE-2025-70516 Fonvil X7A v2.6.0.1182 Websocket认证绕过漏洞
CVE-2025-70517 Fanvil x7a 2.6.0.1182 CSRF漏洞
CVE-2025-70520 Fanvil x7a 2.6.0.1182 认证绕过漏洞
CVE-2025-70519 Fanvil x7a v2.6.0.1182存在存储型XSS漏洞
CVE-2025-70521 Fanvil x7a v2.6.0.1182诊断Ping命令注入漏洞
CVE-2025-70518 Fintel x7a固件2.6.0.1182远程命令执行漏洞
CVE-2025-70522 Fanvil x7a V2.6.0.1182存在CSRF漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-70515

No comments yet


Leave a comment