{"id":"CVE-2025-70522","title":"The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications","summary":"The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary c…","severity":"none","published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T15:57:37.147","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-70522","references":[{"url":"http://download.fanvil.com/Firmware/Release/PA2S/","label":"cve@mitre.org"},{"url":"https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosure","label":"cve@mitre.org"},{"url":"https://www.fanvil.com/products/p5/wulianwangwangguan_1/20210921/5035.html","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-07T15:36:04.050Z","slug":"CVE-2025-70522","body":"## Overview\n\nThe request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}