Impact
Anviz CX2 Lite and CX7 devices are vulnerable because unverified update packages can be uploaded. When such a package is installed, the device unpacks and executes a contained script, leading to unauthenticated remote code execution. The lack of an integrity check allows an attacker to run arbitrary code on the host without authentication, effectively granting full control of the device. This weakness is classified as CWE‑494.
Affected Systems
The affected products are the Anviz CX2 Lite Firmware and the Anviz CX7 Firmware. No additional product versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity vulnerability. The EPSS score of less than 1 % suggests that, as of the current analysis, the probability of exploitation is low, but that does not eliminate the risk to operators who expose the update interface. The vulnerability is not listed in CISA’s KEV catalog. It is inferred that an attacker would need only network access to the firmware upload interface to craft and upload a malicious update package.
OpenCVE Enrichment