Impact
Anviz CX7 Firmware is now described with updated details regarding an authenticated CSV upload that permits path traversal. The vulnerability still allows attackers to overwrite arbitrary files - such as /etc/shadow - by manipulating the upload process, thereby potentially enabling unauthorized SSH access when debug settings are altered. This relative path traversal flaw aligns with CWE-23 and can undermine the confidentiality, integrity, and overall control of the device.
Affected Systems
The affected product is Anviz CX7 Firmware. No specific firmware version details are listed, so all released firmware editions should be considered potentially Anviz.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity. The EPSS score of less than 1% implies a very low predicted exploitation probability at present. The vulnerability is not listed on the CISA KEV catalog. The attack vector requires authenticated access to the CSV upload endpoint; once authenticated, the attacker can overwrite arbitrary files, which may lead to unauthorized SSH access. While the likelihood of exploitation is low now, organizations should treat this as a moderate risk awaiting vendor remediation.
OpenCVE Enrichment