Impact
The vulnerability is a reflected cross‑site scripting flaw located in the device log component of Fanvil x7a firmware version 2.6.0.1182. Malformed user supplied data is not sanitized or encoded before being reflected back into the log page, enabling an attacker to inject arbitrary HTML and execute malicious JavaScript in any browser that renders the log. The impact is execution of code in the victim’s browser, potentially allowing session hijacking, credential theft or further client‑side attacks, but it does not compromise the device itself directly.
Affected Systems
Affected devices are Fanvil x7a units running firmware 2.6.0.1182 or any earlier firmware that contains the untrusted log rendering component. No other vendors or versions are listed.
Risk and Exploitability
No CVSS or EPSS score is available, and the flaw is not listed in CISA’s KEV catalog. Attack requires a victim to view the log page in a browser that renders the injected HTML, which is typically accessed from the device’s web interface by an authenticated user. The exploitation path is straightforward: craft a URL or link containing malicious scripts and persuade or trick the target to load the log page. While client‑side, the flaw can facilitate credential theft and subsequent attacks if the attacker can hijack a logged‑in session. The lack of available exploitation statistics suggests limited public exploitation at present.
OpenCVE Enrichment