Impact
Anviz CX2 Lite and CX7 devices permit unauthenticated POST requests that alter debug settings such as enabling SSH, allowing an attacker to change device configuration without authentication. This flaw is identified as CWE-306 and can facilitate later compromise by granting the attacker the ability to modify system state without proper credentials.
Affected Systems
The vulnerability affects all firmware builds of the Anviz CX2 Lite and Anviz CX7 devices. No specific firmware releases were listed, implying that any current firmware on these models is susceptible unless patched by the vendor.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is <1%, signifying a low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the missing authentication on the debug interface from any network location that can reach the device, so the risk is significant for exposed or poorly segmented networks.
OpenCVE Enrichment