---
id: CVE-2025-64055
title: >-
  An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated
  attackers on the local network to access administrative functions of the
  device (e.g
summary: >-
  An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated
  attackers on the local network to access administrative functions of the
  device (e.g. file upload, firmware update, reboot...) via a crafted
  authentication bypass.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-287
vendor: fanvil
product: x210_firmware
affected:
  - x210_firmware = 2.12.20
published: '2025-12-03'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64055'
references:
  - url: >-
      https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64055.md
    label: cve@mitre.org
  - url: >-
      https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64055.md
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00518
epssPercentile: 0.41574
ingestedAt: '2026-09-25T23:21:16.872Z'
---

## Overview

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass.

## Affected

- `x210_firmware = 2.12.20`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
