CVE-2025-64055

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tenda:x210_firmware:2.12.20:*:*:*:*:*:*:*
cpe:2.3:h:tenda:x210:2.0:*:*:*:*:*:*:*

History

10 Dec 2025, 21:42

Type Values Removed Values Added
First Time Tenda
Tenda x210
Tenda x210 Firmware
CPE cpe:2.3:h:tenda:x210:2.0:*:*:*:*:*:*:*
cpe:2.3:o:tenda:x210_firmware:2.12.20:*:*:*:*:*:*:*
References () http://fanvil.com - () http://fanvil.com - Product
References () https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64055.md - () https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64055.md - Exploit, Third Party Advisory

05 Dec 2025, 20:15

Type Values Removed Values Added
References () https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64055.md - () https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64055.md -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-287

03 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-03 21:15

Updated : 2025-12-10 21:42


NVD link : CVE-2025-64055

Mitre link : CVE-2025-64055

CVE.ORG link : CVE-2025-64055


JSON object : View

Products Affected

tenda

  • x210
  • x210_firmware
CWE
CWE-287

Improper Authentication