Description
Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code execution.
Published: 2026-04-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Anviz CX2 Lite and CX7 devices permit the upload of unverified update packages. When a package is installed, the device automatically unpacks and executes a script contained in the package. The absence of an integrity check allows an attacker to run arbitrary code on the host with no authentication, effectively giving full control of the device. The weakness is classified as CWE‑494.

Affected Systems

The affected products are the Anviz CX2 Lite Firmware and the Anviz CX7 Firmware. No additional product versions are listed in the advisory.

Risk and Exploitability

The CVSS score of 8.8 indicates a high‑severity vulnerability. The EPSS score of less than 1 % suggests that, as of the current analysis, the probability of exploitation is low, but that does not eliminate the risk to operators who expose the update interface. The vulnerability is not listed in CISA’s KEV catalog. An attacker requires only network access to the firmware upload interface; no credentials are necessary, so a local or remote adversary could create a malicious update package and upload it to compromise the device.

Generated by OpenCVE AI on July 27, 2026 at 04:21 UTC.

Remediation

Vendor Workaround

Anviz did not respond to CISA's attempts to coordinate these vulnerabilities. Users should contact Anviz for more information at https://www.anviz.com/contact-us.html .


OpenCVE Recommended Actions

  • Restrict firmware upload to authenticated, digitally signed packages only.
  • Block the firmware upload endpoint using network or device firewall rules to prevent unauthenticated access.
  • Contact Anviz immediately to request an official patch or firmware update that implements integrity checks and authentication.

Generated by OpenCVE AI on July 27, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code execution. Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code execution.

Mon, 04 May 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Anviz cx2 Lite
Anviz cx2 Lite Firmware
Anviz cx7
Anviz cx7 Firmware
CPEs cpe:2.3:h:anviz:cx2_lite:-:*:*:*:*:*:*:*
cpe:2.3:h:anviz:cx7:-:*:*:*:*:*:*:*
cpe:2.3:o:anviz:cx2_lite_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:anviz:cx7_firmware:-:*:*:*:*:*:*:*
Vendors & Products Anviz cx2 Lite
Anviz cx2 Lite Firmware
Anviz cx7
Anviz cx7 Firmware

Fri, 17 Apr 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Anviz
Anviz anviz Cx2 Lite Firmware
Anviz anviz Cx7 Firmware
Vendors & Products Anviz
Anviz anviz Cx2 Lite Firmware
Anviz anviz Cx7 Firmware

Fri, 17 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Apr 2026 19:45:00 +0000

Type Values Removed Values Added
Description Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and executes a script resulting in unauthenticated remote code execution.
Title Anviz Products Download of Code Without Integrity Check
Weaknesses CWE-494
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Anviz Anviz Cx2 Lite Firmware Anviz Cx7 Firmware Cx2 Lite Cx2 Lite Firmware Cx7 Cx7 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-07-10T22:37:11.001Z

Reserved: 2026-04-14T15:47:54.264Z

Link: CVE-2026-40066

cve-icon Vulnrichment

Updated: 2026-04-17T20:00:14.706Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-17T20:16:35.637

Modified: 2026-06-17T10:44:40.650

Link: CVE-2026-40066

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-27T04:30:04Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check