---
id: CVE-2025-70522
title: >-
  The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce
  any cross-origin resource protection for any state-changing request performed
  against the applications
summary: >-
  The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce
  any cross-origin resource protection for any state-changing request performed
  against the applications. Due to the lack of protection, cross-origin boundary
  c…
severity: none
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T15:57:37.147'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-70522'
references:
  - url: 'http://download.fanvil.com/Firmware/Release/PA2S/'
    label: cve@mitre.org
  - url: >-
      https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosure
    label: cve@mitre.org
  - url: 'https://www.fanvil.com/products/p5/wulianwangwangguan_1/20210921/5035.html'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T15:36:04.050Z'
---

## Overview

The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
