CVE-2025-70522
Description
AI Translation Available
The request handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce any cross-origin resource protection for any state-changing request performed against the applications. Due to the lack of protection, cross-origin boundary can be completely bypassed, allowing for Cross-Site Request Forgery Attacks against any endpoint.
http://download.fanvil.com/Firmware/Release/PA2S/
https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosu…
https://www.fanvil.com/products/p5/wulianwangwangguan_1/20210921/5035.html