---
id: CVE-2025-70520
title: >-
  The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not
  enforce proper authentication restrictions against sessionless users
summary: >-
  The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not
  enforce proper authentication restrictions against sessionless users. The lack
  of restrictions grants anyone the ability to view any device resources such as
  operat…
severity: none
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T15:57:37.147'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-70520'
references:
  - url: 'http://download.fanvil.com/Firmware/Release/PA2S/'
    label: cve@mitre.org
  - url: >-
      https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosure
    label: cve@mitre.org
  - url: 'https://www.fanvil.com/products/p5/wulianwangwangguan_1/20210921/5035.html'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T15:36:04.049Z'
---

## Overview

The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
