OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2025-70518 (CVSS 10.0)

NVD · officialPublished Oct 7, 2026Risk 50/100

The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code in the underlying Android operating system.

CVSS
10.0
AV:NetworkAC:LowPR:NoneUI:NoneC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source