---
id: CVE-2025-64057
title: >-
  Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows
  unauthenticated attackers on the local network to store files in arbitrary
  locations and potentially modify the system configuration or other unspecified
  impacts.
summary: >-
  Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows
  unauthenticated attackers on the local network to store files in arbitrary
  locations and potentially modify the system configuration or other unspecified
  impacts.
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H'
cwe:
  - CWE-22
vendor: fanvil
product: x210_firmware
affected:
  - x210_firmware = 2.12.20
published: '2025-12-05'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-64057'
references:
  - url: >-
      https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64057.md
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00811
epssPercentile: 0.5513
ingestedAt: '2026-09-25T23:21:16.894Z'
---

## Overview

Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and potentially modify the system configuration or other unspecified impacts.

## Affected

- `x210_firmware = 2.12.20`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
