CVE-2026-35546

CRITICAL

Anviz Products Missing Authentication for Critical Function

Title source: cna
STIX 2.1

Description

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.

Scores

CVSS v3 9.8
EPSS 0.0059
EPSS Percentile 43.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (4)
Anviz/Anviz CX2 Lite Firmware All versions
Anviz/Anviz CX7 Firmware All versions
anviz/cx2_lite_firmware
anviz/cx7_firmware
Published Apr 17, 2026
Tracked Since Apr 18, 2026