Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-70518

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Fanvil x7a 固件版本 2.6.0.1182 的管理门户诊断 ping 工具未安全处理用户输入。由于缺乏对输入的安全处理,任何未经身份验证的攻击者都可以注入命令并在底层 Android 操作系统中执行代码。

AI Predicted 9.8 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-70518

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2025-70518

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-70518

请登录查看更多情报信息。

Other References for CVE-2025-70518 (3)

Same Patch Batch · n/a · 2026-10-07 · 16 CVEs total

CVE-2026-88514 iTerm2 macOS 低于 3.6.12 本地敏感信息泄露漏洞
CVE-2026-42618 NTFS-3G堆缓冲区溢出漏洞
CVE-2026-46572 ntfs-3G堆缓冲区溢出漏洞
CVE-2026-42616 NTFS-3G heap缓冲区溢出漏洞
CVE-2026-42617 ntfs-3g堆缓冲区溢出漏洞
CVE-2026-46569 ntfs-3G低于2026.7.7的堆缓冲区溢出漏洞
CVE-2026-46571 NTFS-3G 越界读漏洞,影响 2026.7.7 前版本
CVE-2026-46570 NTFS-3G <2026.7.7堆溢出漏洞
CVE-2025-70516 Fonvil X7A v2.6.0.1182 Websocket认证绕过漏洞
CVE-2025-70515 Fanvil x7a 2.6.0.1182存储型XSS漏洞
CVE-2025-70517 Fanvil x7a 2.6.0.1182 CSRF漏洞
CVE-2025-70520 Fanvil x7a 2.6.0.1182 认证绕过漏洞
CVE-2025-70519 Fanvil x7a v2.6.0.1182存在存储型XSS漏洞
CVE-2025-70521 Fanvil x7a v2.6.0.1182诊断Ping命令注入漏洞
CVE-2025-70522 Fanvil x7a V2.6.0.1182存在CSRF漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-70518

No comments yet


Leave a comment