9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted
archives to be accepted, enabling attackers to plant and execute code
and obtain a reverse shell.
archives to be accepted, enabling attackers to plant and execute code
and obtain a reverse shell.
AI Analysis
Unauthenticated firmware upload vulnerability allowing code execution and reverse shell
Basic Information
ID
CVE-2026-35546
Source
icscert
Published
Apr 17, 2026 at 19:39
Affected Product
Vendor
Anviz
Product
Anviz CX7 Firmware
Version
All versions
Affected Versions
Anviz Anviz CX7 Firmware All versions
Anviz Anviz CX2 Lite Firmware All versions
Anviz Anviz CX2 Lite Firmware All versions
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Anviz
Product
Anviz CX2 Lite and CX7
Version
All versions