Impact
The vulnerable component of Fanvil x7a firmware version 2.6.0.1182 fails to properly encode reflected user-supplied data, enabling injection of arbitrary HTML. When the device log component is viewed in a web browser, an attacker can embed JavaScript that executes in the context of the victim’s browser session. Successful exploitation could allow an attacker to steal credentials, hijack the session, deface the interface, or use the victim’s client to launch further attacks against internal resources. The weakness aligns with a classic reflected XSS vulnerability (CWE-79).
Affected Systems
This issue affects all Fanvil x7a devices running firmware 2.6.0.1182. No other firmware revisions or vendor products are listed as impacted in the available data.
Risk and Exploitability
Because the flaw requires that the attacker provide content that is subsequently rendered by a browser, exploitation is possible when a user accesses the log component with malicious input. No EPSS or KEV information is available, so the exact likelihood of exploitation is unknown; however, the ability to inject client-side code presents a high risk whenever the log component is reachable over a network and user input is not sanitized. The vulnerability remains undisclosed in CISA KEV listings.
OpenCVE Enrichment