Impact
The diagnostic ping tool in Fanvil x7a firmware 2.6.0.1182 does not sanitize user‑supplied input, allowing an attacker to inject and execute arbitrary commands on the underlying Android operating system. Because the tool is reachable without authentication, any unauthenticated user can gain full control of the device, compromising confidentiality, integrity, and availability.
Affected Systems
Fanvil x7a VoIP phone running firmware version 2.6.0.1182. No other vendor or product versions are currently known to be affected.
Risk and Exploitability
The vulnerability can be exploited remotely by sending crafted input to the diagnostic ping endpoint. The CVSS score of 10.0 underscores the severity of the issue, and the lack of authentication combined with command injection leads to a high‑risk scenario. EPSS data is unavailable and the issue is not listed in the CISA KEV, but the combination of full code execution and unauthenticated access makes the threat significant. No patch has been reported yet, so the attack remains theoretically high‑severity.
OpenCVE Enrichment