CVE-2025-64057

Directory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrary locations and potentially modify the system configuration or other unspecified impacts.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:fanvil:x210_firmware:2.12.20:*:*:*:*:*:*:*
cpe:2.3:h:fanvil:x210:2.0:*:*:*:*:*:*:*

History

09 Jan 2026, 02:18

Type Values Removed Values Added
First Time Fanvil
Fanvil x210
Fanvil x210 Firmware
CPE cpe:2.3:h:tenda:x210:2.0:*:*:*:*:*:*:*
cpe:2.3:o:tenda:x210_firmware:2.12.20:*:*:*:*:*:*:*
cpe:2.3:o:fanvil:x210_firmware:2.12.20:*:*:*:*:*:*:*
cpe:2.3:h:fanvil:x210:2.0:*:*:*:*:*:*:*
References () https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64057.md - Third Party Advisory, Exploit () https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64057.md - Exploit, Third Party Advisory

10 Dec 2025, 23:10

Type Values Removed Values Added
First Time Tenda
Tenda x210
Tenda x210 Firmware
References () http://fanvil.com - () http://fanvil.com - Product
References () https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64057.md - () https://github.com/SpikeReply/advisories/blob/main/cve/fanvil/cve-2025-64057.md - Third Party Advisory, Exploit
CPE cpe:2.3:h:tenda:x210:2.0:*:*:*:*:*:*:*
cpe:2.3:o:tenda:x210_firmware:2.12.20:*:*:*:*:*:*:*

05 Dec 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.3
CWE CWE-22

05 Dec 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-05 15:15

Updated : 2026-01-09 02:18


NVD link : CVE-2025-64057

Mitre link : CVE-2025-64057

CVE.ORG link : CVE-2025-64057


JSON object : View

Products Affected

fanvil

  • x210
  • x210_firmware
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')