CVE-2025-64055: Fanvil x210 Firmware

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass.

Affected products

  • Fanvil x210 Firmware: version 2.12.20 only

Published 2025-12-03. Last modified 2026-09-25.