Impact
Anviz CX2 Lite and CX7 devices permit the upload of unverified update packages. When a package is installed, the device automatically unpacks and executes a script contained in the package. The absence of an integrity check allows an attacker to run arbitrary code on the host with no authentication, effectively giving full control of the device. The weakness is classified as CWE‑494.
Affected Systems
The affected products are the Anviz CX2 Lite Firmware and the Anviz CX7 Firmware. No additional product versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity vulnerability. The EPSS score of less than 1 % suggests that, as of the current analysis, the probability of exploitation is low, but that does not eliminate the risk to operators who expose the update interface. The vulnerability is not listed in CISA’s KEV catalog. An attacker requires only network access to the firmware upload interface; no credentials are necessary, so a local or remote adversary could create a malicious update package and upload it to compromise the device.
OpenCVE Enrichment