Impact
The firmware for the Fanvil X7a contains a flaw in its WebSocket handler that does not require authentication for session‑less users. An attacker who can reach the WebSocket endpoint can therefore retrieve any device resources, including operational logs and diagnostic data, without providing credentials. This results in a breach of confidentiality, exposing sensitive device information to an unauthenticated actor.
Affected Systems
The affected device is the Fanvil X7a running firmware version 2.6.0.1182; any other devices with the same firmware build are similarly vulnerable.
Risk and Exploitability
Because authentication is not enforced, the vulnerability can be exploited solely by connecting to the WebSocket interface from an external network. No exploitation code or elevated privileges are required, making the attack trivial for anyone with network reach to the device. The exploit probability is unknown as EPSS data is unavailable, but the existence of an unprotected entry point coupled with the ability to read logs represents a high confidentiality risk. The vulnerability is not currently listed in the CISA KEV catalog and no official patch or workaround has been documented by a CNA.
OpenCVE Enrichment