The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 07 Oct 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated WebSocket Access Exposes Device Logs on Fanvil X7A Firmware 2.6.0.1182 | |
| Weaknesses | CWE-284 CWE-285 |
Wed, 07 Oct 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-07T14:45:45.767Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-70516
No data.
Status : Deferred
Published: 2026-10-07T15:16:52.310
Modified: 2026-10-07T15:57:37.147
Link: CVE-2025-70516
No data.
OpenCVE Enrichment
Updated: 2026-10-07T16:30:17Z