Description
The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Client‑side JavaScript Execution via Reflected XSS
Action: Patch Firmware
AI Analysis

Impact

The vulnerability is a reflected cross‑site scripting flaw located in the device log component of Fanvil x7a firmware version 2.6.0.1182. Malformed user supplied data is not sanitized or encoded before being reflected back into the log page, enabling an attacker to inject arbitrary HTML and execute malicious JavaScript in any browser that renders the log. The impact is execution of code in the victim’s browser, potentially allowing session hijacking, credential theft or further client‑side attacks, but it does not compromise the device itself directly.

Affected Systems

Affected devices are Fanvil x7a units running firmware 2.6.0.1182 or any earlier firmware that contains the untrusted log rendering component. No other vendors or versions are listed.

Risk and Exploitability

No CVSS or EPSS score is available, and the flaw is not listed in CISA’s KEV catalog. Attack requires a victim to view the log page in a browser that renders the injected HTML, which is typically accessed from the device’s web interface by an authenticated user. The exploitation path is straightforward: craft a URL or link containing malicious scripts and persuade or trick the target to load the log page. While client‑side, the flaw can facilitate credential theft and subsequent attacks if the attacker can hijack a logged‑in session. The lack of available exploitation statistics suggests limited public exploitation at present.

Generated by OpenCVE AI on October 7, 2026 at 16:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Fanvil x7a firmware that addresses the unsanitized log rendering issue
  • If a newer firmware is not available, place the device on a separate VLAN and restrict administrative access to trusted personnel
  • Configure the device or client browsers to disable JavaScript for the log component as a temporary mitigation

Generated by OpenCVE AI on October 7, 2026 at 16:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Title Reflected XSS Enabling Client‑Side JavaScript Execution in Fanvil x7a Device Log
Weaknesses CWE-79

Wed, 07 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-07T14:45:09.493Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70515

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-07T15:16:51.670

Modified: 2026-10-07T15:57:37.147

Link: CVE-2025-70515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T16:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')