Overview
Three critical vulnerabilities have been disclosed in Fanvil X7A VoIP phone firmware version 2.6.0.1182, an Android-based desk phone / video intercom device marketed to enterprise and SMB telephony deployments. All three were published to NVD on 2026-10-07 and share the same root cause area — the device's websocket-based management portal fails to properly authenticate callers and fails to sanitize input passed to a built-in diagnostic tool.
Two of the three — CVE-2025-70518 (CVSS 10.0) and CVE-2025-70521 (CVSS 9.8) — are unauthenticated command injection flaws in the management portal's diagnostic ping tool, allowing an attacker with no credentials to execute arbitrary commands on the underlying Android operating system. The third, CVE-2025-70516 (CVSS 9.1), is a broken access control flaw in the websocket handler itself: it does not enforce authentication against sessionless users at all, letting anyone pull operational logs or trigger diagnostic requests on the device without ever logging in.
Because the two command injection bugs land directly on an unauthenticated, network-reachable surface with no required user interaction, this set of flaws gives a remote, pre-auth attacker a path straight to code execution on any exposed X7A unit.
Technical Details
| Field | Value |
|---|---|
| CVE IDs | CVE-2025-70518, CVE-2025-70521, CVE-2025-70516 |
| Affected Product | Fanvil X7A (Android-based IP phone) |
| Affected Firmware | 2.6.0.1182 |
| CVE-2025-70518 | CVSS 10.0 — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — CWE-77 (Command Injection) |
| CVE-2025-70521 | CVSS 9.8 — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — CWE-77 (Command Injection) |
| CVE-2025-70516 | CVSS 9.1 — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N — CWE-306 (Missing Authentication for Critical Function) |
| Attack Vector | Network |
| Authentication | None required |
| User Interaction | None required |
| Published | 2026-10-07 (NVD) |
| Patched Version | Not publicly confirmed at time of writing |
Affected Versions
- Fanvil X7A firmware 2.6.0.1182 (confirmed affected per NVD/vendor disclosure)
- No patched firmware build number has been published by Fanvil as of this writing — administrators should monitor Fanvil's official firmware release page for the X7A line and apply any update as soon as one becomes available
Technical Breakdown
CVE-2025-70518 and CVE-2025-70521 — Unauthenticated Command Injection (Diagnostic Ping Tool)
Both CVEs describe the same vulnerable component — the management portal's built-in diagnostic ping tool — and NVD's descriptions for the two are effectively identical, strongly suggesting two overlapping or sibling injection paths into the same feature. According to a third-party disclosure writeup, the ping tool accepts a target host via a websocket request and passes it to a shell command without sanitizing shell metacharacters, so a crafted target value such as a hostname string followed by a shell separator and an arbitrary command executes directly on the device's underlying Android OS. The disclosure describes a proof-of-concept payload resembling 1.1.1.1; touch /sdcard/pwn being accepted and executed by the handler.
Critically, the websocket endpoint behind this feature does not require a logged-in session, so the "diagnostic tool" is reachable by anyone who can send it a websocket request over the network — no credentials, no prior session, and no user interaction on the victim device. That combination of pre-auth reachability and shell command injection is what drives CVE-2025-70518 to a maximum CVSS score of 10.0, and CVE-2025-70521 to 9.8.
CVE-2025-70516 — Websocket Broken Access Control
CVE-2025-70516 covers a separate but related flaw: the websocket handler itself does not enforce authentication restrictions against "sessionless" users. In practice this means the handler never checks whether a caller has an authenticated session before serving requests — so an attacker can retrieve device resources such as operational/diagnostic logs, or trigger diagnostic requests, with no login step at all. This is a textbook CWE-306 (Missing Authentication for Critical Function) issue, and on its own it is an information-disclosure and device-control risk; combined with the command injection paths above, it means the entire management surface behind the websocket handler was effectively exposed without a login wall.
Related Device Family
Third-party disclosure material describes this as part of a broader set of findings affecting both the Fanvil X7A and the related Fanvil PA2S SIP gateway (firmware 2.12.44.9), covering the same command injection and access control bug classes plus separate XSS and CSRF findings tracked under other CVE IDs. Those PA2S- and XSS/CSRF-specific CVEs are outside the scope of this advisory, which covers only the three X7A CVEs assigned CVSS scores of 9.1 or higher.
Impact Assessment
Who Is At Risk
Any organization or individual running a Fanvil X7A unit on firmware 2.6.0.1182 that is reachable on a network where an untrusted party can reach the device's web/websocket management interface, including:
- X7A phones exposed directly to the internet (port-forwarded, or placed on a DMZ/guest VLAN without restriction)
- X7A phones on a flat internal LAN alongside untrusted or compromised endpoints, where lateral movement from another foothold reaches the device
- Multi-tenant or shared-office deployments where the phone's management interface is reachable from other tenants' network segments
Potential Attack Chain
- Discovery — Attacker identifies an X7A device's management websocket endpoint on a reachable network (no authentication needed to probe it)
- Unauthenticated Access (CVE-2025-70516) — Attacker queries the websocket handler directly, pulling operational/diagnostic logs without ever authenticating
- Command Injection (CVE-2025-70518 / CVE-2025-70521) — Attacker sends a crafted diagnostic-ping request containing shell metacharacters, executing arbitrary commands on the device's Android OS
- Persistence / Pivot — With code execution on the phone, an attacker can establish persistence on the device, exfiltrate call logs or configuration data, or use the phone as a pivot point into the surrounding voice/data network
Because a VoIP desk phone frequently sits on the same network segment as other office systems and often has an "always on" uptime profile, a compromised X7A unit is a durable foothold for an attacker, not just a one-off nuisance device.
Mitigation
Immediate Actions
- Restrict network exposure: Do not expose the X7A management interface (web portal / websocket endpoint) to the public internet. Place VoIP phones on an isolated voice VLAN with access limited to management systems and the phone's own SIP/provisioning server.
- Check for a firmware update: No patched firmware version has been publicly confirmed as of this writing — check Fanvil's official firmware release page for the X7A line regularly and apply any update addressing these CVEs as soon as it is available.
- Disable remote/web management where not needed: If the device's web/diagnostic portal is not actively required for day-to-day administration, disable it or restrict it to a management-only network segment.
- Audit exposure now: Identify every X7A unit on your network and confirm its firmware version and network reachability before assuming it is not exposed.
Detection Opportunities
- Monitor network traffic to X7A devices for unexpected websocket connections originating from hosts outside your management network
- Review phone logs (where accessible) for diagnostic/ping requests that do not correspond to known administrative activity
- Watch for unexpected outbound connections or processes on VoIP phones, which may indicate a device has already been used for command execution
Defence-in-Depth
- Segment VoIP/IoT devices onto a dedicated VLAN, isolated from general office and user traffic
- Apply network-level access control lists (ACLs) so only known management hosts can reach phone administration interfaces
- Treat desk phones and similar embedded Android devices as untrusted endpoints in your network architecture — they should not have unrestricted access to internal resources
- Maintain an inventory of VoIP/embedded device firmware versions so future vendor patches can be tracked and applied promptly
Discovery & Disclosure
NVD's published descriptions for all three CVEs do not name a specific researcher or reporting organization. Third-party disclosure material referencing this issue set points to a write-up hosted by Darkpoint Security covering both the Fanvil X7A and the related PA2S gateway, which describes the vulnerable diagnostic ping tool and the websocket authentication gap in similar terms to the NVD descriptions. No CVE Numbering Authority attribution beyond the generic CNA record was available at the time of writing, and no CISA Known Exploited Vulnerabilities (KEV) listing or confirmed in-the-wild exploitation has been reported for any of the three CVEs. Given the unauthenticated, zero-interaction attack path and a maximum CVSS score of 10.0, defenders should treat network exposure of affected devices as an urgent risk regardless of exploitation status.
Key Takeaways
- Three CVEs, one root cause area: CVE-2025-70518, CVE-2025-70521, and CVE-2025-70516 all trace back to the same unauthenticated websocket management surface on Fanvil X7A firmware 2.6.0.1182.
- Unauthenticated RCE is the headline risk: CVE-2025-70518 (CVSS 10.0) and CVE-2025-70521 (CVSS 9.8) let a remote attacker with no credentials execute arbitrary commands on the phone's Android OS via the diagnostic ping tool.
- The access control gap compounds it: CVE-2025-70516 means the websocket handler never even checks for a login, so reconnaissance and log/data exposure require no authentication either.
- No confirmed patch yet: As of publication, no patched firmware build has been publicly confirmed — network isolation is the primary mitigation available today.
- Treat VoIP endpoints as untrusted network citizens: Desk phones and intercoms are often deployed with default or wide-open network access; this disclosure is a reminder to segment and restrict them like any other embedded device.