A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2025-64057

CVE-2025-64057: Fanvil X210 Path Traversal Vulnerability

CVE-2025-64057 is a directory traversal flaw in Fanvil X210 Firmware allowing unauthenticated attackers to store files in arbitrary locations. This article covers technical details, affected versions, and mitigation.

Published: June 16, 2026

CVE-2025-64057 Overview

CVE-2025-64057 is a directory traversal vulnerability [CWE-22] affecting Fanvil X210 V2 IP phones running firmware version 2.12.20. The flaw allows unauthenticated attackers on the local network to write files to arbitrary locations on the device. Successful exploitation can lead to system configuration modification, persistence, and other unspecified impacts on the affected hardware.

The vulnerability is exploitable from an adjacent network without authentication or user interaction. It affects the confidentiality, integrity, and availability of the device, with particularly high impact on integrity and availability.

Critical Impact

Unauthenticated attackers on the same network segment can write arbitrary files to the Fanvil X210 file system, enabling configuration tampering and potential device takeover.

Affected Products

  • Fanvil X210 IP phone (hardware version 2.0)
  • Fanvil X210 firmware version 2.12.20
  • Deployments exposing the device management interface to untrusted local network segments

Discovery Timeline

  • 2025-12-05 - CVE-2025-64057 published to the National Vulnerability Database (NVD)
  • 2026-01-09 - Last updated in NVD database

Technical Details for CVE-2025-64057

Vulnerability Analysis

The Fanvil X210 V2 firmware fails to sanitize file path components supplied to a file upload or storage routine exposed on the local network. An attacker can supply traversal sequences such as ../ within file name or path parameters to escape the intended storage directory. The device then writes attacker-controlled content to arbitrary locations on the underlying file system.

Because the affected endpoint accepts requests without authentication, any host able to reach the device on the LAN can trigger the issue. The attack vector is restricted to the adjacent network rather than the broader internet, but enterprise VoIP deployments often place these phones on shared user VLANs, expanding the realistic attack surface. The EPSS score is 0.795% with a percentile of 51.5, reflecting moderate but non-trivial likelihood of exploitation activity.

Root Cause

The root cause is improper limitation of a pathname to a restricted directory, classified as [CWE-22]. The firmware does not validate, canonicalize, or reject user-supplied path segments before passing them to file write operations. Combined with the absence of authentication on the affected interface, this turns a path handling weakness into a remote unauthenticated file write primitive.

Attack Vector

An attacker on the same Layer 2 or routed local network sends a crafted request containing directory traversal sequences in the target file path. The firmware resolves the path relative to a privileged location and writes attacker-supplied bytes. By targeting configuration files, startup scripts, or web interface assets, the attacker can alter device behavior, redirect SIP traffic, plant persistent backdoors, or render the phone inoperable.

No verified public proof-of-concept is available at this time. See the GitHub CVE-2025-64057 Advisory for technical details.

Detection Methods for CVE-2025-64057

Indicators of Compromise

  • HTTP or proprietary management requests to the Fanvil X210 containing ../ or encoded traversal sequences such as ..%2f in file path parameters
  • Unexpected modifications to device configuration files, firmware assets, or startup scripts on Fanvil X210 endpoints
  • New or altered SIP registration targets, dial plans, or provisioning URLs on affected phones
  • Outbound connections from VoIP phones to hosts that are not part of the approved provisioning or SIP infrastructure

Detection Strategies

  • Inspect network traffic to and from Fanvil X210 devices for traversal patterns in URI paths and POST bodies
  • Baseline configuration hashes of deployed phones and alert on drift between scheduled provisioning cycles
  • Monitor for unauthenticated write operations against the device management interface using IDS or NDR signatures
  • Correlate VoIP device activity with identity and asset inventory to flag rogue or unmanaged hosts initiating management traffic

Monitoring Recommendations

  • Forward syslog and management plane logs from Fanvil devices to a centralized SIEM for retention and correlation
  • Alert on bulk or repeated file upload attempts to phone endpoints from non-administrative source addresses
  • Track firmware versions across the fleet and flag any X210 still on version 2.12.20
  • Review VLAN segmentation and detect any host on a user VLAN scanning for or interacting with VoIP management ports

How to Mitigate CVE-2025-64057

Immediate Actions Required

  • Inventory all Fanvil X210 V2 phones and identify devices running firmware 2.12.20
  • Restrict access to the phone management interface using ACLs or dedicated voice VLANs
  • Block untrusted hosts from reaching VoIP devices on management ports at the switch and firewall layer
  • Audit recent configuration changes on affected phones for signs of tampering

Patch Information

No vendor advisory URL is listed in the NVD record at the time of writing. Administrators should consult the Fanvil Official Website for firmware updates superseding version 2.12.20 and apply patched firmware to all affected X210 devices once available. Until a fix is released, treat the devices as exposed and apply compensating network controls.

Workarounds

  • Place all VoIP phones on a dedicated, isolated voice VLAN that is not reachable from user or guest networks
  • Enforce 802.1X port authentication so only known endpoints can communicate with phone management services
  • Disable any unused remote management or auto-provisioning features on the phone where supported by firmware settings
  • Restrict provisioning server communication to known IP addresses using firewall rules
bash
# Example: restrict access to Fanvil X210 management interface on an IOS-style switch
ip access-list extended VOICE_MGMT_PROTECT
  permit ip host 10.10.20.10 10.20.0.0 0.0.255.255   # provisioning server to phones
  deny   ip any           10.20.0.0 0.0.255.255       # block all other management traffic
  permit ip any any
!
interface range GigabitEthernet1/0/1 - 48
  ip access-group VOICE_MGMT_PROTECT in

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypePath Traversal

  • Vendor/TechFanvil

  • SeverityHIGH

  • CVSS Score8.3

  • EPSS Probability0.80%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-22
  • Technical References
  • Fanvil Official Website

  • GitHub CVE-2025-64057 Advisory
  • Related CVEs
  • CVE-2025-64054: Fanvil X210 Firmware XSS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English