Impact
Anviz CX7 Firmware allows an unauthenticated POST request to the device that triggers the front‑facing camera to capture a photo. The captured image reveals visual information about the deployment environment, enabling an attacker to gain exposure of internal settings or personnel without authentication. This weakness is a lack of authorization (CWE‑862) and results in the disclosure of confidential visual data.
Affected Systems
The affected product is Anviz CX7 Firmware from Anviz; specific version details are not provided in the advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no confirmed exploitable instances yet. The attack vector is inferred to be remote network access to the device, as the vulnerability is triggered via an unauthenticated POST request. While the exploitability is uncertain, the potential for unauthorized exposure of environment images warrants attention.
OpenCVE Enrichment