External risk intelligence

Fanvil x7a Firmware Command Injection Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2025-70518

The vulnerability exists in the management portal of a network-connected communication device. Management interfaces on such devices are frequently deployed in environments where they are accessible via the network, and the vulnerability is unauthenticated, increasing the likelihood of exposure if the device management interface is reachable.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in the management portal of certain Fanvil communication devices. The issue allows unauthenticated attackers to inject commands and execute code on the device's operating system. This could potentially lead to a compromise of the device and any connected systems or data.

  • Unauthenticated code execution in device management.
  • Compromise could affect device and connected systems.
  • Confirm relevance and exposure to connected devices.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could access the management portal's diagnostic ping tool to inject commands. This could allow them to execute arbitrary code on the device's operating system.

  • No authentication required.
  • Triggered via the diagnostic ping tool.
  • Allows unauthenticated remote code execution.

Live Threat

Current exploitation, exposure, and threat context

The management portal's diagnostic ping tool on the Fanvil x7a can be exploited by an unauthenticated attacker to inject commands and execute arbitrary code on the underlying Android operating system. This could affect the device's functionality and potentially compromise its security.

  • Device's operating system integrity.
  • Command injection via ping tool.
  • Complete device compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Fanvil devices' management portal requires immediate attention from teams responsible for managing network-connected communication endpoints. The first practical step is to identify all deployed Fanvil devices, determine their network exposure and business criticality, and then confirm the accountable owner for remediation.

  • Identify and confirm accountable device owners.
  • Verify network exposure and business criticality.
  • Plan remediation based on identified risks.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Fanvil x7a?

The Fanvil x7a is a professional, touch-screen desktop VoIP phone that runs on the Android operating system. It serves as a network-connected communication endpoint used in business environments to manage calls, video, and contacts. Because it functions like a small computer, it includes a web-based management portal that allows administrators to configure network settings and perform system diagnostics.

What does command injection mean in CVE-2025-70518?

This vulnerability is classified as CWE-77, or Improper Neutralization of Special Elements used in a Command. In this case, the device's diagnostic ping tool fails to filter or sanitize data entered by a user. An attacker can take advantage of this by entering malicious system commands instead of a standard network address, causing the device to execute those commands with administrative privileges within its Android operating system.

How is this vulnerability triggered?

An attacker triggers the vulnerability by accessing the device's diagnostic ping tool through the management portal. Importantly, this requires no login or password, as the interface does not verify the user's identity. The vulnerability is not triggered by normal phone usage, such as making calls or navigating the standard user interface; it specifically requires interaction with the administrative diagnostic feature.

Is my device at risk?

According to Halo Surface Signal, this vulnerability is likely to be reachable if the management portal is accessible over your network. If these devices are connected to networks where the management interface is reachable by unauthorized users, the risk is higher. You should assess whether your phone's web management portal is exposed to the internet or accessible from untrusted segments of your internal network.

How do I respond to this vulnerability?

Start by identifying all Fanvil x7a devices within your network and confirming who is responsible for their maintenance. Once identified, evaluate whether the web management interface is accessible to unauthorized users and prioritize restricting network access to these portals. You should then check for and apply official firmware updates provided by the manufacturer to remediate the underlying issue.

References