More information about this CVE will likely be available in a few days
Description
The websocket handler of Fanvil x7a firmware version 2.6.0.1182 does not enforce proper authentication restrictions against sessionless users. The lack of restrictions grants anyone the ability to view any device resources such as operational logs or perform diagnostic requests.
Related CPE's
Could not find any relations
References
Weaknesses
Could not find any weaknesses
CVSS impact metrics
Could not find any metrics
Information
Source identifier
Vulnerability status
Deferred
Published
2026-10-07T15:16:54.640Z
41 hours agoLast modified
2026-10-07T15:57:37.147Z
41 hours ago