Description
Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.
Published: 2026-04-17
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Anviz CX7 Firmware is now described with updated details regarding an authenticated CSV upload that permits path traversal. The vulnerability still allows attackers to overwrite arbitrary files - such as /etc/shadow - by manipulating the upload process, thereby potentially enabling unauthorized SSH access when debug settings are altered. This relative path traversal flaw aligns with CWE-23 and can undermine the confidentiality, integrity, and overall control of the device.

Affected Systems

The affected product is Anviz CX7 Firmware. No specific firmware version details are listed, so all released firmware editions should be considered potentially Anviz.

Risk and Exploitability

The CVSS score of 4.9 indicates a moderate severity. The EPSS score of less than 1% implies a very low predicted exploitation probability at present. The vulnerability is not listed on the CISA KEV catalog. The attack vector requires authenticated access to the CSV upload endpoint; once authenticated, the attacker can overwrite arbitrary files, which may lead to unauthorized SSH access. While the likelihood of exploitation is low now, organizations should treat this as a moderate risk awaiting vendor remediation.

Generated by OpenCVE AI on July 26, 2026 at 00:29 UTC.

Remediation

Vendor Workaround

Anviz did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Anviz for more information at https://www.anviz.com/contact-us.html .


OpenCVE Recommended Actions

  • Contact Anviz support at https://www.anviz.com/contact-us.html to request a patch or detailed mitigation guidance.
  • Restrict CSV upload access to the minimum set of trusted users and disable the feature entirely if it is not required for operations.
  • Configure input validation or enforce path restrictions on uploads so that filenames containing ".." or absolute paths are rejected; if the firmware does not support these checks, use network policies to block the upload service from directories containing critical system files.
  • Audit device logs for unexpected file modifications and consider disabling debug setting changes or SSH access to limit potential damage until a vendor fix is applied.

Generated by OpenCVE AI on July 26, 2026 at 00:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.

Mon, 04 May 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Anviz cx7
Anviz cx7 Firmware
CPEs cpe:2.3:h:anviz:cx7:-:*:*:*:*:*:*:*
cpe:2.3:o:anviz:cx7_firmware:-:*:*:*:*:*:*:*
Vendors & Products Anviz cx7
Anviz cx7 Firmware

Fri, 17 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Apr 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Anviz
Anviz anviz Cx7 Firmware
Vendors & Products Anviz
Anviz anviz Cx7 Firmware

Fri, 17 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
Description Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes
Title Anviz CX7 Firmware Relative Path Traversal
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Anviz Anviz Cx7 Firmware Cx7 Cx7 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-10T22:35:14.120Z

Reserved: 2026-04-14T15:42:14.030Z

Link: CVE-2026-31927

cve-icon Vulnrichment

Updated: 2026-04-17T20:34:33.930Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-17T20:16:33.370

Modified: 2026-06-17T10:34:46.450

Link: CVE-2026-31927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T00:30:04Z

Weaknesses
  • CWE-23

    Relative Path Traversal