Impact
Fanvil X7A firmware version 2.6.0.1182 lacks cross‑origin resource protection for state‑changing requests, allowing attackers to perform Cross‑Site Request Forgery. The vulnerability enables an attacker to trick an authenticated user or the device itself into executing unintended actions, potentially compromising configuration, data, or service availability. Because the flaw is in the request handler, attackers do not need additional privileges and can exploit it from a malicious web page or script.
Affected Systems
The Fanvil x7a VoIP phone running firmware 2.6.0.1182 is affected. No other vendors or product versions are currently reported as vulnerable.
Risk and Exploitability
No CVSS score is available and the EPSS score is not published; the vulnerability is not listed in CISA KEV. The typical attack vector is through a malicious web site or page that forces the user's browser to issue authenticated requests to the x7a. As the flaw permits unrestricted state changes without CSRF protection, the likelihood of exploitation is considered moderate to high for targets that expose the device’s management interface to the internet. Attacks would succeed without needing to locate or exploit additional weaknesses.
OpenCVE Enrichment