Description
The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.
Published: 2026-10-07
Score: n/a
EPSS: n/a
KEV: No
Impact: Information Disclosure via Unauthenticated WebSocket Access
Action: Immediate Patch
AI Analysis

Impact

The firmware for the Fanvil X7a contains a flaw in its WebSocket handler that does not require authentication for session‑less users. An attacker who can reach the WebSocket endpoint can therefore retrieve any device resources, including operational logs and diagnostic data, without providing credentials. This results in a breach of confidentiality, exposing sensitive device information to an unauthenticated actor.

Affected Systems

The affected device is the Fanvil X7a running firmware version 2.6.0.1182; any other devices with the same firmware build are similarly vulnerable.

Risk and Exploitability

Because authentication is not enforced, the vulnerability can be exploited solely by connecting to the WebSocket interface from an external network. No exploitation code or elevated privileges are required, making the attack trivial for anyone with network reach to the device. The exploit probability is unknown as EPSS data is unavailable, but the existence of an unprotected entry point coupled with the ability to read logs represents a high confidentiality risk. The vulnerability is not currently listed in the CISA KEV catalog and no official patch or workaround has been documented by a CNA.

Generated by OpenCVE AI on October 7, 2026 at 16:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied firmware update that enforces WebSocket authentication for the X7a product.
  • Configure network firewalls or VLAN rules to block unsolicited traffic to the device’s WebSocket ports from non‑trusted networks.
  • If a patch is not immediately available, disable or restrict external access to the WebSocket service via device or network configuration to limit exposure.

Generated by OpenCVE AI on October 7, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated WebSocket Access Exposes Device Logs on Fanvil X7a
Weaknesses CWE-284
CWE-287

Wed, 07 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
Description The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-07T14:48:24.547Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70520

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-07T15:16:54.640

Modified: 2026-10-07T15:57:37.147

Link: CVE-2025-70520

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T16:30:17Z

Weaknesses