Fanvil manufactures a focused line of IP telephony and VoIP communication devices, with its vulnerability profile concentrated in the X210 handset and its firmware. The disclosures recur across a pattern of memory-safety and input-validation weaknesses—including classic buffer overflows, command injection, path traversal, cross-site scripting, and authentication bypass—that are characteristic of embedded communication devices, and these vulnerabilities skew strongly toward critical-severity outcomes. Defenders should prioritize inventory and patching of affected devices, particularly in networked environments; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fanvil over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64055CRITICAL An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmwa | Dec 3, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-64054CRITICAL A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via craf | Dec 5, 2025 | 9.6 | 32 | NO | NO |
CVE-2025-64057HIGH Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and potentially modify the s | Dec 5, 2025 | 8.3 | 31 | NO | NO |
CVE-2025-64053HIGH A Buffer overflow vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial of service or potentially execute arbitrary commands via crafted POST request to t | Dec 5, 2025 | 7.5 | 29 | NO | NO |
CVE-2025-64052MEDIUM An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arbitrary system commands. | Dec 5, 2025 | 5.1 | 23 | NO | NO |
CVE-2025-64056MEDIUM File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbitrary files on the filesystem. | Dec 5, 2025 | 4.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fanvil.
Media articles that mention a CVE ID that affects a product developed by Fanvil — matched by CVE ID, not by vendor name.