Description
The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting
Action: Mitigate
AI Analysis

Impact

The vulnerable component of Fanvil x7a firmware version 2.6.0.1182 fails to properly encode reflected user-supplied data, enabling injection of arbitrary HTML. When the device log component is viewed in a web browser, an attacker can embed JavaScript that executes in the context of the victim’s browser session. Successful exploitation could allow an attacker to steal credentials, hijack the session, deface the interface, or use the victim’s client to launch further attacks against internal resources. The weakness aligns with a classic reflected XSS vulnerability (CWE-79).

Affected Systems

This issue affects all Fanvil x7a devices running firmware 2.6.0.1182. No other firmware revisions or vendor products are listed as impacted in the available data.

Risk and Exploitability

Because the flaw requires that the attacker provide content that is subsequently rendered by a browser, exploitation is possible when a user accesses the log component with malicious input. No EPSS or KEV information is available, so the exact likelihood of exploitation is unknown; however, the ability to inject client-side code presents a high risk whenever the log component is reachable over a network and user input is not sanitized. The vulnerability remains undisclosed in CISA KEV listings.

Generated by OpenCVE AI on October 7, 2026 at 16:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict or disable external access to the device log component so that only authenticated and authorized staff can view it.
  • Ensure any content displayed in the log is sanitized or properly HTML‑escaped before rendering in the browser.
  • If the log component is not required, disable it entirely or limit its availability to internal networks only.

Generated by OpenCVE AI on October 7, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Title Reflected Cross‑Site Scripting in Fanvil x7a Log Component
Weaknesses CWE-79

Wed, 07 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description The device log component of Fanvil x7a firmware version 2.6.0.1182 does not properly sanitize or encode reflected user supplied data. The lack of sanitization allows for the injection of HTML which can be used to execute malicious JavaScript code on any target browser which renders the device log component.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-07T14:47:48.847Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70519

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-07T15:16:53.903

Modified: 2026-10-07T15:57:37.147

Link: CVE-2025-70519

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T17:00:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')